Junglewise Threat Intelligence

CVE-2026-64168: Linux Kernel Spreadtrum SPI driver error pointer dereference in DMA setup

CVE-2026-64168 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's SPI driver for Spreadtrum (Unisoc) devices. The issue occurs when the system fails to set up Direct Memory Access (DMA) and incorrectly attempts to clean up resources that were never successfully initialized. This could lead to a system crash or instability (kernel panic) during the hardware initialization process.

Technical details

A vulnerability exists in 'drivers/spi/spi-sprd.c' within the Linux kernel due to improper error handling during the driver probe sequence. When DMA setup fails, the driver is designed to fall back to Programmed I/O (PIO) mode; however, subsequent errors in the probe process trigger a cleanup routine that attempts to release DMA channels without verifying if they were successfully allocated. This results in a dereference of an ERR_PTR or a double-release of DMA resources. The fix introduces a check for the 'dma.enabled' flag in the 'release_dma' error path to ensure 'sprd_spi_dma_release' is only called when appropriate.

Affected products

  • Linux Linux 5.1 to 5.10.258, 5.15.209, 6.1.175, 6.6.103, 6.12.y

Timeline

  • 2026-05-12: other: Patch authored by Johan Hovold
  • 2026-07-19: disclosed: CVE published

References