Use-After-Free Vulnerability in Linux Kernel's TI-QSPI Driver
CVE-2026-64221
What is CVE-2026-64221?
A use-after-free vulnerability has been identified in the TI-QSPI driver within the Linux kernel. The vulnerability arises during the DMA setup process where, upon failure, the system does not properly clear the DMA channel pointer. This oversight may lead to further references of a released channel and subsequent unintended behaviors, raising the risk of security issues. The flaw was highlighted during a review of a devres allocation conversion patch, prompting necessary fixes to enhance stability and security in the affected driver.
Affected Version(s)
Linux c687c46e9e4527c4b4d82bc3cca58c1b08bcfb83 < 9c6f306a8140962c7284197db54b96fdb5f468d6
Linux c687c46e9e4527c4b4d82bc3cca58c1b08bcfb83 < 3bbbe7ae3fdada0df4157c1ffe989f92dfa8dcd6
Linux c687c46e9e4527c4b4d82bc3cca58c1b08bcfb83