CVE-2026-31389

Source
https://cve.org/CVERecord?id=CVE-2026-31389
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31389.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-31389
Downstream
Related
Published
2026-04-03T15:15:55.068Z
Modified
2026-06-03T08:44:14.920276779Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
spi: fix use-after-free on controller registration failure
Details

In the Linux kernel, the following vulnerability has been resolved:

spi: fix use-after-free on controller registration failure

Make sure to deregister from driver core also in the unlikely event that per-cpu statistics allocation fails during controller registration to avoid use-after-free (of driver resources) and unclocked register accesses.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31389.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6598b91b5ac32bc756d7c3000a31f775d4ead1c4
Fixed
0e23f50086da7d0b183dfeac26021acfcdee086b
Fixed
6bbd385b30c7fb6c7ee0669e9ada91490938c051
Fixed
afe27c1f43aa57530011f419be6ddf71306565d2
Fixed
80f3e8cd2b4ad355b2ad2024cf423f6d183404f7
Fixed
23b51bad2eb8787aa74324cfccefb258515ae5ba
Fixed
8634e05b08ead636e926022f4a98416e13440df9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31389.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.1.167
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.130
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.20
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.10

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31389.json"