CVE-2026-23475 — Access of Uninitialized Pointer in Linux
Severity
5.5MEDIUM
No vectorEPSS
0.0%
top 90.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 3
Description
In the Linux kernel, the following vulnerability has been resolved:
spi: fix statistics allocation
The controller per-cpu statistics is not allocated until after the
controller has been registered with driver core, which leaves a window
where accessing the sysfs attributes can trigger a NULL-pointer
dereference.
Fix this by moving the statistics allocation to controller allocation
while tying its lifetime to that of the controller (rather than using
implicit devres).
Affected Packages3 packages
▶CVEListV5linux/linux6598b91b5ac32bc756d7c3000a31f775d4ead1c4 — 80c5bd0dca1cc5526ae0f4b273ccd163ed4caa4e+6
🔴Vulnerability Details
2GHSA▶
GHSA-p23v-v2wc-73m3: In the Linux kernel, the following vulnerability has been resolved:
spi: fix statistics allocation
The controller per-cpu statistics is not allocate↗2026-04-03
OSV▶
CVE-2026-23475: In the Linux kernel, the following vulnerability has been resolved: spi: fix statistics allocation The controller per-cpu statistics is not allocated↗2026-04-03