Driver Vulnerability in Linux Kernel for QUP SPI Interface
CVE-2026-64170

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64170?

In the Linux kernel, a significant issue was identified regarding the QUP SPI interface driver, where a fallback mechanism to PIO mode could result in dereferencing an error pointer. This problem arises when DMA setup fails during the driver's initialization process. To mitigate this, it is essential to clear the DMA channel pointers to avoid potential errors on subsequent probe attempts or when unbinding the driver. This vulnerability was highlighted during a review of a development resource allocation conversion patch, bringing attention to the need for secure coding practices to enhance driver reliability.

Affected Version(s)

Linux 612762e82ae6058d69b4ce734598491bf030afe7 < 0bb3bd442f0bdad3932739a61dd6c580c9c1955e

Linux 612762e82ae6058d69b4ce734598491bf030afe7

Linux 612762e82ae6058d69b4ce734598491bf030afe7 < 9e673affb92c29d9ba879bf4ea81c5e840166b56

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.