CVE-2026-93814
In the Linux kernel, the following vulnerability has been resolved:
spi: core: Abort active target transfer on controller suspend
When an SPI controller operating in target mode has a transfer in progress at the time of system suspend, the suspend path proceeds without aborting the ongoing transfer. This can leave the hardware in an inconsistent state, potentially causing the system to hang or fail to resume cleanly.
Fix this by invoking the controller's target_abort callback from spi_controller_suspend() when the controller is in target mode and the callback is registered. This ensures any active target transfer is cleanly terminated before the controller is suspended.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1cc84ca8599b8fa64014821bca453ebb3326c71e
- https://git.kernel.org/stable/c/a75d9eb78c89d3fa8d503966c91a51f02eced768
- https://git.kernel.org/stable/c/b81ac605763c319ca9928a237818ab4e8ab7bb59
- https://git.kernel.org/stable/c/c1bab046d4786c5b17aab7c5225bf0d4a2a2d19b
- https://git.kernel.org/stable/c/f6a0cafa265c8a4aed585d873747e3b88b146eed
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93814",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6c364062bfed3c34490e85bea52ff6e2d4f0f281",
"lessThan": "a75d9eb78c89d3fa8d503966c91a51f02eced768",
"versionType": "git"
},
{
"status": "affected",
"version": "6c364062bfed3c34490e85bea52ff6e2d4f0f281",
"lessThan": "1cc84ca8599b8fa64014821bca453ebb3326c71e",
"versionType": "git"
},
{
"status": "affected",
"version": "6c364062bfed3c34490e85bea52ff6e2d4f0f281",
"lessThan": "b81ac605763c319ca9928a237818ab4e8ab7bb59",
"versionType": "git"
},
{
"status": "affected",
"version": "6c364062bfed3c34490e85bea52ff6e2d4f0f281",
"lessThan": "f6a0cafa265c8a4aed585d873747e3b88b146eed",
"versionType": "git"
},
{
"status": "affected",
"version": "6c364062bfed3c34490e85bea52ff6e2d4f0f281",
"lessThan": "c1bab046d4786c5b17aab7c5225bf0d4a2a2d19b",
"versionType": "git"
}
],
"programFiles": [
"drivers/spi/spi.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/spi/spi.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:14.897",
"references": [
{
"url": "https://git.kernel.org/stable/c/1cc84ca8599b8fa64014821bca453ebb3326c71e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a75d9eb78c89d3fa8d503966c91a51f02eced768",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b81ac605763c319ca9928a237818ab4e8ab7bb59",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c1bab046d4786c5b17aab7c5225bf0d4a2a2d19b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f6a0cafa265c8a4aed585d873747e3b88b146eed",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: core: Abort active target transfer on controller suspend\n\nWhen an SPI controller operating in target mode has a transfer in\nprogress at the time of system suspend, the suspend path proceeds\nwithout aborting the ongoing transfer. This can leave the hardware in\nan inconsistent state, potentially causing the system to hang or fail\nto resume cleanly.\n\nFix this by invoking the controller's target_abort callback from\nspi_controller_suspend() when the controller is in target mode and the\ncallback is registered. This ensures any active target transfer is\ncleanly terminated before the controller is suspended."
}
],
"lastModified": "2026-10-03T11:17:51.293",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}