CVE-2026-31389
spi: fix use-after-free on controller registration failure
Description
In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from driver core also in the unlikely event that per-cpu statistics allocation fails during controller registration to avoid use-after-free (of driver resources) and unclocked register accesses.
INFO
Published Date :
April 3, 2026, 4:16 p.m.
Last Modified :
July 24, 2026, 10:10 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Apply the patch for SPI controller registration failure.
- Ensure per-cpu statistics allocation succeeds.
- Deregister driver resources on allocation failure.
- Avoid unclocked register accesses.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-31389.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-31389 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-31389
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-31389 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-31389 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 24, 2026
Action Type Old Value New Value Added Translation Title: Linux, Description: En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: spi: corrección de uso después de liberación en caso de fallo de registro del controlador Asegúrese de anular el registro del núcleo del controlador también en el improbable caso de que falle la asignación de estadísticas por CPU durante el registro del controlador para evitar el uso después de liberación (de recursos del controlador) y los accesos a registros sin reloj. -
CVE Modified by 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Jul. 14, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'Siemens', 'product': 'SIMATIC S7-1500 CPU 1518-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.6', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'Siemens', 'product': 'SIMATIC S7-1500 CPU 1518-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.5', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'Siemens', 'product': 'SIMATIC S7-1500 CPU 1518-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.6', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'Siemens', 'product': 'SIMATIC S7-1500 CPU 1518-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.5', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'Siemens', 'product': 'SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.6', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'Siemens', 'product': 'SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.5', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'Siemens', 'product': 'SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.6', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'Siemens', 'product': 'SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.5', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'Siemens', 'product': 'SIPLUS S7-1500 CPU 1518-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.6', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}, {'vendor': 'Siemens', 'product': 'SIPLUS S7-1500 CPU 1518-4 PN/DP MFP', 'versions': [{'status': 'affected', 'version': 'V3.1.5', 'lessThan': '*', 'versionType': 'custom'}], 'defaultStatus': 'unknown'}] Added Reference https://cert-portal.siemens.com/productcert/html/ssa-019113.html Added Reference https://cert-portal.siemens.com/productcert/html/ssa-082556.html -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6598b91b5ac32bc756d7c3000a31f775d4ead1c4', 'lessThan': '0e23f50086da7d0b183dfeac26021acfcdee086b', 'versionType': 'git'}, {'status': 'affected', 'version': '6598b91b5ac32bc756d7c3000a31f775d4ead1c4', 'lessThan': '6bbd385b30c7fb6c7ee0669e9ada91490938c051', 'versionType': 'git'}, {'status': 'affected', 'version': '6598b91b5ac32bc756d7c3000a31f775d4ead1c4', 'lessThan': 'afe27c1f43aa57530011f419be6ddf71306565d2', 'versionType': 'git'}, {'status': 'affected', 'version': '6598b91b5ac32bc756d7c3000a31f775d4ead1c4', 'lessThan': '80f3e8cd2b4ad355b2ad2024cf423f6d183404f7', 'versionType': 'git'}, {'status': 'affected', 'version': '6598b91b5ac32bc756d7c3000a31f775d4ead1c4', 'lessThan': '23b51bad2eb8787aa74324cfccefb258515ae5ba', 'versionType': 'git'}, {'status': 'affected', 'version': '6598b91b5ac32bc756d7c3000a31f775d4ead1c4', 'lessThan': '8634e05b08ead636e926022f4a98416e13440df9', 'versionType': 'git'}], 'programFiles': ['drivers/spi/spi.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '6.0'}, {'status': 'unaffected', 'version': '0', 'lessThan': '6.0', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.167', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.130', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.78', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.20', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '6.19.10', 'versionType': 'semver', 'lessThanOrEqual': '6.19.*'}, {'status': 'unaffected', 'version': '7.0', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/spi/spi.c'], 'defaultStatus': 'affected'}] -
Initial Analysis by [email protected]
May. 20, 2026
Action Type Old Value New Value Added CWE CWE-416 Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.130 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.78 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.20 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 6.19.10 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.0 up to (excluding) 6.1.167 Added Reference Type kernel.org: https://git.kernel.org/stable/c/0e23f50086da7d0b183dfeac26021acfcdee086b Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/23b51bad2eb8787aa74324cfccefb258515ae5ba Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/6bbd385b30c7fb6c7ee0669e9ada91490938c051 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/80f3e8cd2b4ad355b2ad2024cf423f6d183404f7 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/8634e05b08ead636e926022f4a98416e13440df9 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/afe27c1f43aa57530011f419be6ddf71306565d2 Types: Patch -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Apr. 27, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Apr. 03, 2026
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from driver core also in the unlikely event that per-cpu statistics allocation fails during controller registration to avoid use-after-free (of driver resources) and unclocked register accesses. Added Reference https://git.kernel.org/stable/c/0e23f50086da7d0b183dfeac26021acfcdee086b Added Reference https://git.kernel.org/stable/c/23b51bad2eb8787aa74324cfccefb258515ae5ba Added Reference https://git.kernel.org/stable/c/6bbd385b30c7fb6c7ee0669e9ada91490938c051 Added Reference https://git.kernel.org/stable/c/80f3e8cd2b4ad355b2ad2024cf423f6d183404f7 Added Reference https://git.kernel.org/stable/c/8634e05b08ead636e926022f4a98416e13440df9 Added Reference https://git.kernel.org/stable/c/afe27c1f43aa57530011f419be6ddf71306565d2