Executive brief
A vulnerability was identified in the Linux kernel's SPI QUP driver, which manages communication between the processor and peripheral devices. Under certain conditions where high-speed data transfer (DMA) fails to initialize, the system could attempt to use invalid memory addresses. This could lead to a system crash or instability, potentially impacting the availability of devices relying on this driver.
Technical details
In the Linux kernel SPI QUP driver (`drivers/spi/spi-qup.c`), a vulnerability exists where DMA channel pointers are not cleared after a setup failure during the probe process. Although the driver correctly falls back to Programmed I/O (PIO) mode, the stale error pointers remain in the `dma_tx` and `dma_rx` fields. This can result in an error pointer dereference or an attempt to release the same DMA channel a second time during subsequent probe errors or when the driver is unbound. The fix involves explicitly setting these pointers to NULL in the error handling path of `spi_qup_init_dma`.
Affected products
- Linux Linux 4.1 to 6.13
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory
References
- https://git.kernel.org/stable/c/0bb3bd442f0bdad3932739a61dd6c580c9c1955e
- https://git.kernel.org/stable/c/45760b72e84c1a1498f1a8a9047184c85299da20
- https://git.kernel.org/stable/c/4bb4764f2c51f03f657a28029eb0595d8223aab5
- https://git.kernel.org/stable/c/4f4051e9d644c371c50de4a042b85bba6727d5c3
- https://git.kernel.org/stable/c/8f9b61d255b1e989b8913b06c8ebe0aba5e1b238
- https://git.kernel.org/stable/c/9e673affb92c29d9ba879bf4ea81c5e840166b56
- https://git.kernel.org/stable/c/a7e8f3efd50a165ba0189f6dc57f7e51a7d149db