CVE-2026-64303
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2026
Last modified:
25/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
spi: fsl-lpspi: terminate the RX channel on TX prepare failure path<br />
<br />
When dmaengine_prep_slave_sg() fails for the TX channel, the error path<br />
terminates the TX DMA channel but leaves the RX channel running. Since<br />
the RX channel was already submitted and issued prior to preparing<br />
the TX descriptor, returning -EINVAL causes the SPI core to unmap the<br />
DMA buffers while the RX DMA engine continues writing to them, leading<br />
to potential memory corruption or use-after-free.<br />
<br />
Terminate the RX channel before returning on the TX prepare failure path.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/01980b5da56e573d62798d0ff6c86bcaa2b22cbe
- https://git.kernel.org/stable/c/808033d80d5c9f8adf7e8de9317389270ce13430
- https://git.kernel.org/stable/c/9d000bdd250d649a11cd7f733175686877344582
- https://git.kernel.org/stable/c/ad370d1c7a9a832f77b2341513cd31188c9443af
- https://git.kernel.org/stable/c/af39a2698f69b584d14a00cffe0f51a2caa15337
- https://git.kernel.org/stable/c/cce2063404b2341e7b2bbf85eddfcd70a31a0033
- https://git.kernel.org/stable/c/d5c1060218a3749c8a18b36f8169d910fce20639
- https://git.kernel.org/stable/c/e65505d91fa036a238968e4c10744244d1b968c4



