Vulnerability in Linux Kernel: Error Pointer Dereference in DMA Setup
CVE-2026-64168

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64168?

A vulnerability has been identified in the Linux kernel concerning the SPI driver for specific device operations. When the Direct Memory Access (DMA) setup fails during the device probing process, the driver incorrectly handles the fallback to Programmed Input/Output (PIO) mode. This can lead to dereferencing an error pointer if the dma.enabled flag is not properly checked, which may cause crashes or undefined behavior. The issue was addressed to ensure reliable memory management and prevent the release of DMA channels when probing errors occur.

Affected Version(s)

Linux 386119bc7be9fa5114ced0274a22a943df890b4b

Linux 386119bc7be9fa5114ced0274a22a943df890b4b

Linux 386119bc7be9fa5114ced0274a22a943df890b4b < 0cdea166c1a07c200caf9d0b722224fca43b23ae

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.