« Volver al listado

CVE-2026-72048

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ieee802154: ca8210: fix cas_ctl leak on spi_async failure

ca8210_spi_transfer() allocates cas_ctl with kzalloc_obj(GFP_ATOMIC) and relies entirely on the SPI completion callback ca8210_spi_transfer_complete() to free it.

The spi_async() API only invokes the completion callback on successful submission. On failure it returns a negative error code without ever queuing the callback, which leaves cas_ctl and its embedded spi_message and spi_transfer orphaned. Every kfree(cas_ctl) in the driver is inside the completion callback, so there is no other reclamation path.

Leer descripción completaMostrar menos

ca8210_spi_transfer() is called from ca8210_spi_exchange(), the interrupt handler ca8210_interrupt_handler(), and from the retry path inside the completion callback itself. The exchange and interrupt handler paths loop on -EBUSY, so under sustained SPI bus contention every retry iteration leaks a fresh cas_ctl (~600 bytes per occurrence).

Fix it by freeing cas_ctl on the spi_async() error path. While here, correct the misleading error string: the function calls spi_async(), not spi_sync().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72048",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ded845a781a578dfb0b5b2c138e5a067aa3b1242",
              "lessThan": "460c5cd51e4d7d15b317f178f42cfcb666c0fe91",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ded845a781a578dfb0b5b2c138e5a067aa3b1242",
              "lessThan": "b07aea90dbc6e188c74c100af64b77b9482ffc65",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ded845a781a578dfb0b5b2c138e5a067aa3b1242",
              "lessThan": "fe90605b651573d30be8293ff5be40e3d7023117",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ded845a781a578dfb0b5b2c138e5a067aa3b1242",
              "lessThan": "b9071dc7889bef42590e04fbf3e56cc65e1e5e6e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ded845a781a578dfb0b5b2c138e5a067aa3b1242",
              "lessThan": "d4a397fe803c2d157f6ebb068b802ef75fbf109e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ded845a781a578dfb0b5b2c138e5a067aa3b1242",
              "lessThan": "cb5cca1d2a908ddd5e357971de0f2009617b8d6a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ded845a781a578dfb0b5b2c138e5a067aa3b1242",
              "lessThan": "7e3630fbb6aabb844bbf35746dee0bf3894100c7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ded845a781a578dfb0b5b2c138e5a067aa3b1242",
              "lessThan": "e09390e439bd7cca30dd10893b1f64802961667a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ieee802154/ca8210.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ieee802154/ca8210.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:14.050",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/460c5cd51e4d7d15b317f178f42cfcb666c0fe91",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7e3630fbb6aabb844bbf35746dee0bf3894100c7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b07aea90dbc6e188c74c100af64b77b9482ffc65",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b9071dc7889bef42590e04fbf3e56cc65e1e5e6e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cb5cca1d2a908ddd5e357971de0f2009617b8d6a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d4a397fe803c2d157f6ebb068b802ef75fbf109e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e09390e439bd7cca30dd10893b1f64802961667a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fe90605b651573d30be8293ff5be40e3d7023117",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: ca8210: fix cas_ctl leak on spi_async failure\n\nca8210_spi_transfer() allocates cas_ctl with kzalloc_obj(GFP_ATOMIC)\nand relies entirely on the SPI completion callback\nca8210_spi_transfer_complete() to free it.\n\nThe spi_async() API only invokes the completion callback on successful\nsubmission.  On failure it returns a negative error code without ever\nqueuing the callback, which leaves cas_ctl and its embedded spi_message\nand spi_transfer orphaned.  Every kfree(cas_ctl) in the driver is\ninside the completion callback, so there is no other reclamation path.\n\nca8210_spi_transfer() is called from ca8210_spi_exchange(), the\ninterrupt handler ca8210_interrupt_handler(), and from the retry path\ninside the completion callback itself.  The exchange and interrupt\nhandler paths loop on -EBUSY, so under sustained SPI bus contention\nevery retry iteration leaks a fresh cas_ctl (~600 bytes per\noccurrence).\n\nFix it by freeing cas_ctl on the spi_async() error path.  While here,\ncorrect the misleading error string: the function calls spi_async(),\nnot spi_sync()."
    }
  ],
  "lastModified": "2026-08-17T06:18:02.860",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}