CVE-2026-46296
Estado: AnalizadaMedia (5.5)—
In the Linux kernel, the following vulnerability has been resolved:
spi: s3c64xx: fix NULL-deref on driver unbind
A change moving DMA channel allocation from probe() back to s3c64xx_spi_prepare_transfer() failed to remove the corresponding deallocation from remove().
Drop the bogus DMA channel release from remove() to avoid triggering a NULL-pointer dereference on driver unbind.
This issue was flagged by Sashiko when reviewing a controller deregistration fix.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-476
Referencias
- https://git.kernel.org/stable/c/1108b8722b9ff0cdd3e8aa18d98244fcd93b6760
- https://git.kernel.org/stable/c/1b66f16a571a10ba8889ac471755c8af9c5b9266
- https://git.kernel.org/stable/c/22788b1a8611380b141e09a8896702e32d164238
- https://git.kernel.org/stable/c/29e219a18e21258bdb4ee12cecd0e9ec87d7e6a7
- https://git.kernel.org/stable/c/323a258f4b1916b5a3098618e036e033b2f2317f
- https://git.kernel.org/stable/c/45daacbead8a009844bd5dba6cfa731332184d17
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-46296",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f52b03c707444c5a3d1a0b9c5724f93ddc3c588e",
"lessThan": "29e219a18e21258bdb4ee12cecd0e9ec87d7e6a7",
"versionType": "git"
},
{
"status": "affected",
"version": "f52b03c707444c5a3d1a0b9c5724f93ddc3c588e",
"lessThan": "1108b8722b9ff0cdd3e8aa18d98244fcd93b6760",
"versionType": "git"
},
{
"status": "affected",
"version": "f52b03c707444c5a3d1a0b9c5724f93ddc3c588e",
"lessThan": "323a258f4b1916b5a3098618e036e033b2f2317f",
"versionType": "git"
},
{
"status": "affected",
"version": "f52b03c707444c5a3d1a0b9c5724f93ddc3c588e",
"lessThan": "1b66f16a571a10ba8889ac471755c8af9c5b9266",
"versionType": "git"
},
{
"status": "affected",
"version": "f52b03c707444c5a3d1a0b9c5724f93ddc3c588e",
"lessThan": "22788b1a8611380b141e09a8896702e32d164238",
"versionType": "git"
},
{
"status": "affected",
"version": "f52b03c707444c5a3d1a0b9c5724f93ddc3c588e",
"lessThan": "45daacbead8a009844bd5dba6cfa731332184d17",
"versionType": "git"
}
],
"programFiles": [
"drivers/spi/spi-s3c64xx.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.140",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.88",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.30",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.7",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/spi/spi-s3c64xx.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-06-08T17:16:48.037",
"references": [
{
"url": "https://git.kernel.org/stable/c/1108b8722b9ff0cdd3e8aa18d98244fcd93b6760",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1b66f16a571a10ba8889ac471755c8af9c5b9266",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/22788b1a8611380b141e09a8896702e32d164238",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/29e219a18e21258bdb4ee12cecd0e9ec87d7e6a7",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/323a258f4b1916b5a3098618e036e033b2f2317f",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/45daacbead8a009844bd5dba6cfa731332184d17",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-476"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: s3c64xx: fix NULL-deref on driver unbind\n\nA change moving DMA channel allocation from probe() back to\ns3c64xx_spi_prepare_transfer() failed to remove the corresponding\ndeallocation from remove().\n\nDrop the bogus DMA channel release from remove() to avoid triggering a\nNULL-pointer dereference on driver unbind.\n\nThis issue was flagged by Sashiko when reviewing a controller\nderegistration fix."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nspi: s3c64xx: corrige desreferencia NULL al desvincular el controlador\n\nUn cambio que movió la asignación del canal DMA de probe() de vuelta a s3c64xx_spi_prepare_transfer() no eliminó la desasignación correspondiente de remove().\n\nEliminar la liberación errónea del canal DMA de remove() para evitar activar una desreferencia de puntero NULL al desvincular el controlador.\n\nEste problema fue señalado por Sashiko al revisar una corrección de desregistro del controlador."
}
],
"lastModified": "2026-07-23T08:10:00.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8D193E9E-2E9B-468E-B920-AD1EA1BA82C7",
"versionEndExcluding": "6.1.176",
"versionStartIncluding": "6.0"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1A92866-F406-43B5-B2D1-CFC274753E9D",
"versionEndExcluding": "6.6.140",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5AFBE0EC-CCDF-4207-AE92-ABF958125CA4",
"versionEndExcluding": "6.12.88",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF39AE08-AE6D-4410-8FBE-76F6BF5BF55B",
"versionEndExcluding": "6.18.30",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0893CA7-9AE6-4DFE-AC75-48967D73AD8E",
"versionEndExcluding": "7.0.7",
"versionStartIncluding": "6.19"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}