cbcvebase.
CVE-2026-23207
published 2026-02-14

CVE-2026-23207: In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer check in IRQ handler Now that all other accesses to…

PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.09%
0.5th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer check in IRQ handler Now that all other accesses to curr_xfer are done under the lock, protect the curr_xfer NULL check in tegra_qspi_isr_thread() with the spinlock. Without this protection, the following race can occur: CPU0 (ISR thread) CPU1 (timeout path) ---------------- ------------------- if (!tqspi->curr_xfer) // sees non-NULL spin_lock() tqspi->curr_xfer = NULL spin_unlock() handle_*_xfer() spin_lock() t = tqspi->curr_xfer // NULL! ... t->len ... // NULL dereference! With this patch, all curr_xfer accesses are now properly synchronized. Although all accesses to curr_xfer are done under the lock, in tegra_qspi_isr_thread() it checks for NULL, releases the lock and reacquires it later in handle_cpu_based_xfer()/handle_dma_based_xfer(). There is a potential for an update in between, which could cause a NULL pointer dereference. To handle this, add a NULL check inside the handlers after acquiring the lock. This ensures that if the timeout path has already cleared curr_xfer, the handler will safely return without dereferencing the NULL pointer.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.10-1 (forky)linux 6.18.10-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 01bbf25c767219b14c3235bfa85906b8d2cb8fbc < 2ac3a105e51496147c0e44e49466eecfcc532d572ac3a105e51496147c0e44e49466eecfcc532d57
linuxlinux>= 5.15.198 < 5.165.16
linuxlinux>= 551060efb156c50fe33799038ba8145418cfdeef < 84e926c1c272a35ddb9b86842d32fa833a60dfc784e926c1c272a35ddb9b86842d32fa833a60dfc7
linuxlinux>= 6.1.160 < 6.26.2
linuxlinux>= 6.12.63 < 6.12.806.12.80
linuxlinux>= 6.17.13 < 6.186.18
linuxlinux>= 6.18.2 < 6.18.106.18.10
linuxlinux>= 6.6.120 < 6.76.7
linuxlinux>= b4e002d8a7cee3b1d70efad0e222567f92a73000 < edf9088b6e1d6d88982db7eb5e736a0e4fbcc09eedf9088b6e1d6d88982db7eb5e736a0e4fbcc09e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 5.15.198 < 5.165.16
linuxlinux_kernel>= 6.1.160 < 6.26.2
linuxlinux_kernel>= 6.12.63 < 6.136.13
linuxlinux_kernel>= 6.17.13 < 6.186.18
linuxlinux_kernel>= 6.18.2 < 6.18.106.18.10
linuxlinux_kernel>= 6.6.120 < 6.76.7
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.