« Volver al listado

CVE-2026-23202

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer

The curr_xfer field is read by the IRQ handler without holding the lock to check if a transfer is in progress. When clearing curr_xfer in the combined sequence transfer loop, protect it with the spinlock to prevent a race with the interrupt handler.

Protect the curr_xfer clearing at the exit path of tegra_qspi_combined_seq_xfer() with the spinlock to prevent a race with the interrupt handler that reads this field.

Without this protection, the IRQ handler could read a partially updated curr_xfer value, leading to NULL pointer dereference or use-after-free.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-23202",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-23202",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-10T20:41:13.077528Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "88db8bb7ed1bb474618acdf05ebd4f0758d244e2",
              "lessThan": "9fa4262a80f751d14a6a39d2c03f57db68da2618",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "83309dd551cfd60a5a1a98d9cab19f435b44d46d",
              "lessThan": "762e2ce71c8f0238e9eaf05d14da803d9a24422f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c934e40246da2c5726d14e94719c514e30840df8",
              "lessThan": "712cde8d916889e282727cdf304a43683adf899e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "551060efb156c50fe33799038ba8145418cfdeef",
              "lessThan": "6fd446178a610a48e80e5c5b487b0707cd01daac",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01bbf25c767219b14c3235bfa85906b8d2cb8fbc",
              "lessThan": "3bc293d5b56502068481478842f57b3d96e432c7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4e002d8a7cee3b1d70efad0e222567f92a73000",
              "lessThan": "bf4528ab28e2bf112c3a2cdef44fd13f007781cd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bb0c58be84f907285af45657c1d4847b960a12bf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.17.13",
              "lessThan": "6.18",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/spi/spi-tegra210-quad.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15.198",
              "lessThan": "5.15.200",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.160",
              "lessThan": "6.1.163",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.120",
              "lessThan": "6.6.124",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.63",
              "lessThan": "6.12.70",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.2",
              "lessThan": "6.18.10",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/spi/spi-tegra210-quad.c"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-02-14T17:15:58.050",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3bc293d5b56502068481478842f57b3d96e432c7",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6fd446178a610a48e80e5c5b487b0707cd01daac",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/712cde8d916889e282727cdf304a43683adf899e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/762e2ce71c8f0238e9eaf05d14da803d9a24422f",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9fa4262a80f751d14a6a39d2c03f57db68da2618",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bf4528ab28e2bf112c3a2cdef44fd13f007781cd",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer\n\nThe curr_xfer field is read by the IRQ handler without holding the lock\nto check if a transfer is in progress. When clearing curr_xfer in the\ncombined sequence transfer loop, protect it with the spinlock to prevent\na race with the interrupt handler.\n\nProtect the curr_xfer clearing at the exit path of\ntegra_qspi_combined_seq_xfer() with the spinlock to prevent a race\nwith the interrupt handler that reads this field.\n\nWithout this protection, the IRQ handler could read a partially updated\ncurr_xfer value, leading to NULL pointer dereference or use-after-free."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nspi: tegra210-quad: Proteger curr_xfer en tegra_qspi_combined_seq_xfer\n\nEl campo curr_xfer es leído por el manejador IRQ sin mantener el bloqueo para verificar si una transferencia está en curso. Al limpiar curr_xfer en el bucle de transferencia de secuencia combinada, protegerlo con el spinlock para evitar una condición de carrera con el manejador de interrupciones.\n\nProteger la limpieza de curr_xfer en la ruta de salida de tegra_qspi_combined_seq_xfer() con el spinlock para evitar una condición de carrera con el manejador de interrupciones que lee este campo.\n\nSin esta protección, el manejador IRQ podría leer un valor curr_xfer parcialmente actualizado, lo que llevaría a una desreferencia de puntero NULL o uso después de liberación."
    }
  ],
  "lastModified": "2026-06-17T10:21:05.447",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9086ED9F-28EF-4E81-ACC8-DD9C0694960D",
              "versionEndExcluding": "5.15.200",
              "versionStartIncluding": "5.15.198"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD2D07F5-E7EF-418E-8FCC-7EA75E155311",
              "versionEndExcluding": "6.1.163",
              "versionStartIncluding": "6.1.160"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "589180AE-205F-411A-BB02-6DCA1C9766FE",
              "versionEndExcluding": "6.6.124",
              "versionStartIncluding": "6.6.120"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEECD823-DAFD-40C2-AFA9-F4E308AB7796",
              "versionEndExcluding": "6.12.70",
              "versionStartIncluding": "6.12.63"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C298528-1754-41BD-B4E9-84A37AB7BA32",
              "versionEndExcluding": "6.18",
              "versionStartIncluding": "6.17.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EF65418-FC18-4809-98E5-14B1A2C57DF8",
              "versionEndExcluding": "6.18.10",
              "versionStartIncluding": "6.18.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17B67AA7-40D6-4AFA-8459-F200F3D7CFD1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C47E4CC9-C826-4FA9-B014-7FE3D9B318B2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F71D92C0-C023-48BD-B3B6-70B638EEE298"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13580667-0A98-40CC-B29F-D12790B91BDB"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CAD1FED7-CF48-47BF-AC7D-7B6FA3C065FC"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EF854A1-ABB1-4E93-BE9A-44569EC76C0D"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5DC0CA6-F0AF-4DDF-A882-3DADB9A886A7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB5B7DFC-C36B-45D8-922C-877569FDDF43"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}