Security Flaw in Linux Kernel Affecting SPI Driver Functionality
CVE-2026-64169

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64169?

A vulnerability exists in the Linux kernel's SPI driver, where an error pointer may be dereferenced after a failure in direct memory access (DMA) setup. When the DMA setup fails during probe, the driver falls back to programmable input/output (PIO) mode without properly clearing the DMA channel pointers. This oversight can lead to dereferencing an invalid pointer during subsequent probe errors or driver unbind processes, posing potential stability and security concerns within the Linux environment.

Affected Version(s)

Linux e79e7c2df6277ee1ad9364a231f6183da4492415

Linux e79e7c2df6277ee1ad9364a231f6183da4492415 < 8e027db9fa310b1d5e7ad928510be800c4f004d9

Linux e79e7c2df6277ee1ad9364a231f6183da4492415 < 0e2189ab095e3657f37b8295f3f2bbcde0f27529

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.