CVE-2026-64303

Source
https://cve.org/CVERecord?id=CVE-2026-64303
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64303.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64303
Downstream
Published
2026-07-25T08:49:38.223Z
Modified
2026-07-27T04:03:21.147707788Z
Summary
spi: fsl-lpspi: terminate the RX channel on TX prepare failure path
Details

In the Linux kernel, the following vulnerability has been resolved:

spi: fsl-lpspi: terminate the RX channel on TX prepare failure path

When dmaengineprepslave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX channel running. Since the RX channel was already submitted and issued prior to preparing the TX descriptor, returning -EINVAL causes the SPI core to unmap the DMA buffers while the RX DMA engine continues writing to them, leading to potential memory corruption or use-after-free.

Terminate the RX channel before returning on the TX prepare failure path.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64303.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
09c04466ce7ea494993c0635ba5edb6d2222a806
Fixed
ad370d1c7a9a832f77b2341513cd31188c9443af
Fixed
cce2063404b2341e7b2bbf85eddfcd70a31a0033
Fixed
af39a2698f69b584d14a00cffe0f51a2caa15337
Fixed
e65505d91fa036a238968e4c10744244d1b968c4
Fixed
d5c1060218a3749c8a18b36f8169d910fce20639
Fixed
808033d80d5c9f8adf7e8de9317389270ce13430
Fixed
9d000bdd250d649a11cd7f733175686877344582
Fixed
01980b5da56e573d62798d0ff6c86bcaa2b22cbe

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64303.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64303.json"