Junglewise Threat Intelligence

CVE-2026-64170: Linux kernel error pointer dereference in SPI QUP driver

CVE-2026-64170 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's SPI QUP driver, which manages communication between the processor and peripheral devices. Under certain conditions where high-speed data transfer (DMA) fails to initialize, the system could attempt to use invalid memory addresses. This could lead to a system crash or instability, potentially impacting the availability of devices relying on this driver.

Technical details

In the Linux kernel SPI QUP driver (`drivers/spi/spi-qup.c`), a vulnerability exists where DMA channel pointers are not cleared after a setup failure during the probe process. Although the driver correctly falls back to Programmed I/O (PIO) mode, the stale error pointers remain in the `dma_tx` and `dma_rx` fields. This can result in an error pointer dereference or an attempt to release the same DMA channel a second time during subsequent probe errors or when the driver is unbound. The fix involves explicitly setting these pointers to NULL in the error handling path of `spi_qup_init_dma`.

Affected products

  • Linux Linux 4.1 to 6.13

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References