Executive brief
A vulnerability was identified in the Linux kernel's TI QSPI storage driver. When the system fails to set up a high-speed data transfer mode (DMA), it may incorrectly keep a reference to memory that has already been freed. This could lead to system instability or a potential security breach if an attacker can trigger this specific failure condition.
Technical details
A use-after-free vulnerability exists in drivers/spi/spi-ti-qspi.c within the Linux kernel. The issue occurs during the driver probe phase when DMA setup fails; while the driver correctly falls back to PIO mode and releases the DMA channel, it fails to nullify the rx_chan pointer. This results in a dangling pointer that may be passed to the DMA engine or lead to a double-free during driver unbind or subsequent probe errors. The fix involves explicitly setting the channel pointer to NULL after release. Patches have been backported to multiple stable kernel branches including 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.12.y, and 6.13.y.
Affected products
- Linux Linux Kernel 4.12 to 5.10.258, 5.15.209, 6.1.175, 6.6.75, 6.12.12, 6.13.1
Timeline
- 2026-05-12: patched: Initial patch authored by Johan Hovold
- 2026-07-24: disclosed: CVE-2026-64221 published
References
- https://git.kernel.org/stable/c/178b9b570c0f75fa7e691490520328b20d19138e
- https://git.kernel.org/stable/c/1cd927002120678bd5d23c760246639caa53040e
- https://git.kernel.org/stable/c/3bbbe7ae3fdada0df4157c1ffe989f92dfa8dcd6
- https://git.kernel.org/stable/c/9c6f306a8140962c7284197db54b96fdb5f468d6
- https://git.kernel.org/stable/c/d6f422b122922d1abee907d673bcc990e5f3672d
- https://git.kernel.org/stable/c/d7a076fb596c7b408ed6df74793a597990a6d860
- https://git.kernel.org/stable/c/ea6ec3343e05f7937a53eb6d7617b3abdb4abc19