spi: ti-qspi: fix use-after-free after DMA setup failure
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
spi: ti-qspi: fix use-after-free after DMA setup failure
The driver falls back to PIO mode if DMA setup fails during probe.
Make sure to clear the DMA channel pointer also if buffer allocation
fails to avoid passing a pointer to the released channel to the DMA
engine (or trying to free the channel a second time on late probe errors
or driver unbind).
This issue was flagged by Sashiko when reviewing a devres allocation
conversion patch.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/178b9b570c0f75fa7e691490520328b20d19138ehttps://git.kernel.org/stable/c/1cd927002120678bd5d23c760246639caa53040ehttps://git.kernel.org/stable/c/3bbbe7ae3fdada0df4157c1ffe989f92dfa8dcd6https://git.kernel.org/stable/c/9c6f306a8140962c7284197db54b96fdb5f468d6https://git.kernel.org/stable/c/d6f422b122922d1abee907d673bcc990e5f3672dhttps://git.kernel.org/stable/c/d7a076fb596c7b408ed6df74793a597990a6d860https://git.kernel.org/stable/c/ea6ec3343e05f7937a53eb6d7617b3abdb4abc19https://git.kernel.org/stable/c/f2dc841d7dc9063fe9b47ced869b1271e55052ae