cbcvebase.
CVE-2026-23202
published 2026-02-14

CVE-2026-23202: In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer The curr_xfer field…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.5th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer The curr_xfer field is read by the IRQ handler without holding the lock to check if a transfer is in progress. When clearing curr_xfer in the combined sequence transfer loop, protect it with the spinlock to prevent a race with the interrupt handler. Protect the curr_xfer clearing at the exit path of tegra_qspi_combined_seq_xfer() with the spinlock to prevent a race with the interrupt handler that reads this field. Without this protection, the IRQ handler could read a partially updated curr_xfer value, leading to NULL pointer dereference or use-after-free.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 01bbf25c767219b14c3235bfa85906b8d2cb8fbc < 3bc293d5b56502068481478842f57b3d96e432c73bc293d5b56502068481478842f57b3d96e432c7
linuxlinux>= 5.15.198 < 5.15.2005.15.200
linuxlinux>= 551060efb156c50fe33799038ba8145418cfdeef < 6fd446178a610a48e80e5c5b487b0707cd01daac6fd446178a610a48e80e5c5b487b0707cd01daac
linuxlinux>= 6.1.160 < 6.1.1636.1.163
linuxlinux>= 6.12.63 < 6.12.706.12.70
linuxlinux>= 6.17.13 < 6.186.18
linuxlinux>= 6.18.2 < 6.18.106.18.10
linuxlinux>= 6.6.120 < 6.6.1246.6.124
linuxlinux>= 83309dd551cfd60a5a1a98d9cab19f435b44d46d < 762e2ce71c8f0238e9eaf05d14da803d9a24422f762e2ce71c8f0238e9eaf05d14da803d9a24422f
linuxlinux>= 88db8bb7ed1bb474618acdf05ebd4f0758d244e2 < 9fa4262a80f751d14a6a39d2c03f57db68da26189fa4262a80f751d14a6a39d2c03f57db68da2618
linuxlinux>= b4e002d8a7cee3b1d70efad0e222567f92a73000 < bf4528ab28e2bf112c3a2cdef44fd13f007781cdbf4528ab28e2bf112c3a2cdef44fd13f007781cd
linuxlinux>= c934e40246da2c5726d14e94719c514e30840df8 < 712cde8d916889e282727cdf304a43683adf899e712cde8d916889e282727cdf304a43683adf899e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 5.15.198 < 5.15.2005.15.200
linuxlinux_kernel>= 6.1.160 < 6.1.1636.1.163
linuxlinux_kernel>= 6.12.63 < 6.12.706.12.70
linuxlinux_kernel>= 6.17.13 < 6.186.18
linuxlinux_kernel>= 6.18.2 < 6.18.106.18.10
linuxlinux_kernel>= 6.6.120 < 6.6.1246.6.124

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.