CVE-2026-90410

Source
https://cve.org/CVERecord?id=CVE-2026-90410
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90410.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90410
Downstream
Published
2026-09-17T16:09:37Z
Modified
2026-09-18T03:48:38Z
Summary
spi: davinci: switch to managed controller allocation
Details

In the Linux kernel, the following vulnerability has been resolved:

spi: davinci: switch to managed controller allocation

The controller is allocated with the non-managed spi_alloc_host() while the interrupt is registered with devm_request_threaded_irq(). During removal, spi_bitbang_stop() only unregisters the controller; the subsequent spi_controller_put() then frees the controller together with its embedded davinci_spi devdata, which is the IRQ handler's dev_id. The devm_request_threaded_irq() release action (free_irq()), which drains the handler, does not run until after .remove() returns. A late or latched interrupt can therefore reach davinci_spi_irq() and dereference already-freed memory.

Switch to devm_spi_alloc_host() so that the devres LIFO order releases the controller only after free_irq() has drained the handler, and drop the now-redundant spi_controller_put() from .remove(). The probe error path is simplified to direct returns.

The clock is acquired with devm_clk_get_enabled(), which is registered after the IRQ and thus released before it by the devres LIFO order. Drain the interrupt explicitly with devm_free_irq() before disabling the controller so that a late interrupt cannot access the registers of a clock-gated controller.

This issue was found by an in-house static analysis tool.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90410.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5b3bb5963ff23a344062aba04937533a6f575761
Fixed
29e37f768f35592e26477f703649bd2e6f18d857
Fixed
f9452eba71fbfcee55c0b8e030ee3615e9f75f65
Fixed
3b544072185c3d19ddec621ec9f6897ea2d10ee3
Fixed
1a7958ce58dc95b06615df00c120ece4eb9ccc86
Fixed
ea408a05dc8f18b4a184b88d6e19d2fd1acc1527

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90410.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.14.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90410.json"