CVE-2026-31389
published 2026-04-03CVE-2026-31389: In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
1.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
spi: fix use-after-free on controller registration failure
Make sure to deregister from driver core also in the unlikely event that
per-cpu statistics allocation fails during controller registration to
avoid use-after-free (of driver resources) and unclocked register
accesses.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.10-1 (forky) | linux 6.19.10-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 6598b91b5ac32bc756d7c3000a31f775d4ead1c4 < 0e23f50086da7d0b183dfeac26021acfcdee086b | 0e23f50086da7d0b183dfeac26021acfcdee086b |
| linux | linux | >= 6598b91b5ac32bc756d7c3000a31f775d4ead1c4 < 6bbd385b30c7fb6c7ee0669e9ada91490938c051 | 6bbd385b30c7fb6c7ee0669e9ada91490938c051 |
| linux | linux | >= 6598b91b5ac32bc756d7c3000a31f775d4ead1c4 < afe27c1f43aa57530011f419be6ddf71306565d2 | afe27c1f43aa57530011f419be6ddf71306565d2 |
| linux | linux | >= 6598b91b5ac32bc756d7c3000a31f775d4ead1c4 < 80f3e8cd2b4ad355b2ad2024cf423f6d183404f7 | 80f3e8cd2b4ad355b2ad2024cf423f6d183404f7 |
| linux | linux | >= 6598b91b5ac32bc756d7c3000a31f775d4ead1c4 < 23b51bad2eb8787aa74324cfccefb258515ae5ba | 23b51bad2eb8787aa74324cfccefb258515ae5ba |
| linux | linux | >= 6598b91b5ac32bc756d7c3000a31f775d4ead1c4 < 8634e05b08ead636e926022f4a98416e13440df9 | 8634e05b08ead636e926022f4a98416e13440df9 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.10-1 | 6.19.10-1 |
| linux | linux_kernel | >= 6.0 < 6.1.167 | 6.1.167 |
| linux | linux_kernel | >= 6.13 < 6.18.20 | 6.18.20 |
| linux | linux_kernel | >= 6.19 < 6.19.10 | 6.19.10 |
| linux | linux_kernel | >= 6.2 < 6.6.130 | 6.6.130 |
| linux | linux_kernel | >= 6.7 < 6.12.78 | 6.12.78 |
| ubuntu | linux | — | — |
| ubuntu | linux-fips | — | — |
| ubuntu | linux-gcp | — | — |
| ubuntu | linux-gcp-6.8 | — | — |
| ubuntu | linux-gcp-fips | — | — |
| ubuntu | linux-gke | — | — |
| ubuntu | linux-gkeop | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat4.7MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Oracle) vulnerabilities
vendor_ubuntu·2026-07-23·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel (Oracle) vulnerabilities
Title: Linux kernel (Oracle) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A loca
Ubuntu
Linux kernel (NVIDIA) vulnerabilities
vendor_ubuntu·2026-07-23·CVSS 2.0
CVE-2026-43129 [LOW] Linux kernel (NVIDIA) vulnerabilities
Title: Linux kernel (NVIDIA) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A loca
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-23·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacke
Ubuntu
Linux kernel (GCP FIPS) vulnerabilities
vendor_ubuntu·2026-07-21·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel (GCP FIPS) vulnerabilities
Title: Linux kernel (GCP FIPS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A lo
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 2.0
CVE-2026-46073 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting in privilege escalation. (CVE-2025-54518)
It was discovered that some AMD Zen 5 processors supporting RDSEED
instruction did not properly handle entropy, potentially resulting in the
consumption of insufficiently random values. A local attacke
Red Hat
kernel: spi: fix use-after-free on controller registration failure
vendor_redhat·2026-04-03·CVSS 4.7
CVE-2026-31389 [MEDIUM] CWE-825 kernel: spi: fix use-after-free on controller registration failure
kernel: spi: fix use-after-free on controller registration failure
In the Linux kernel, the following vulnerability has been resolved:
spi: fix use-after-free on controller registration failure
Make sure to deregister from driver core also in the unlikely event that
per-cpu statistics allocation fails during controller registration to
avoid use-after-free (of driver resources) and unclocked register
accesses.
A flaw was found in the Linux kernel's Serial Peripheral Interface (SPI) subsystem. During controller registration, a use-after-free vulnerability can occur if the allocation of per-CPU statistics fails. This could allow a local attacker to cause system instability or a denial of service by accessing freed memory.
Statement: This vulnerability occurs only during an unlikely error p
Debian
CVE-2026-31389: linux - In the Linux kernel, the following vulnerability has been resolved: spi: fix us...
vendor_debian·2026
CVE-2026-31389 CVE-2026-31389: linux - In the Linux kernel, the following vulnerability has been resolved: spi: fix us...
In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from driver core also in the unlikely event that per-cpu statistics allocation fails during controller registration to avoid use-after-free (of driver resources) and unclocked register accesses.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 6.19.10-1)
sid: resolved (fixed in 6.19.10-1)
trixie: open
VulDB
Linux Kernel up to 7.0-rc4 spi use after free (Nessus ID 311783)
vuldb·2026-05-04·CVSS 7.8
CVE-2026-31389 [HIGH] Linux Kernel up to 7.0-rc4 spi use after free (Nessus ID 311783)
A vulnerability classified as critical has been found in Linux Kernel up to 7.0-rc4. This affects an unknown part of the component spi. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-31389. The attacker must have access to the local network to execute the attack. No exploit exists.
It is recommended to upgrade the affected component.
OSV
CVE-2026-31389: In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister
osv·2026-04-03
CVE-2026-31389 CVE-2026-31389: In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister
In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration failure Make sure to deregister from driver core also in the unlikely event that per-cpu statistics allocation fails during controller registration to avoid use-after-free (of driver resources) and unclocked register accesses.
GHSA
GHSA-7jq8-3vqq-qc62: In the Linux kernel, the following vulnerability has been resolved:
spi: fix use-after-free on controller registration failure
Make sure to deregist
ghsa_unreviewed·2026-04-03
CVE-2026-31389 GHSA-7jq8-3vqq-qc62: In the Linux kernel, the following vulnerability has been resolved:
spi: fix use-after-free on controller registration failure
Make sure to deregist
In the Linux kernel, the following vulnerability has been resolved:
spi: fix use-after-free on controller registration failure
Make sure to deregister from driver core also in the unlikely event that
per-cpu statistics allocation fails during controller registration to
avoid use-after-free (of driver resources) and unclocked register
accesses.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-31389 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2026-31389 CVE-2026-31389 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-31389 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
spi: fix use-after-free on controller registration failure
Make sure to deregister from driver core also in the unlikely event that
per-cpu statistics allocation fails during controller registration to
avoid use-after-free (of driver resources) and unclocked register
accesses.
Source : NVD
Published April 3, 2026
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-rt-64k-debug
kernel-64k-debug-modules-core
Sourc
Bugzilla
CVE-2026-31389 kernel: spi: fix use-after-free on controller registration failure
bugzilla·2026-04-03·CVSS 7.8
CVE-2026-31389 [HIGH] CVE-2026-31389 kernel: spi: fix use-after-free on controller registration failure
CVE-2026-31389 kernel: spi: fix use-after-free on controller registration failure
In the Linux kernel, the following vulnerability has been resolved:
spi: fix use-after-free on controller registration failure
Make sure to deregister from driver core also in the unlikely event that
per-cpu statistics allocation fails during controller registration to
avoid use-after-free (of driver resources) and unclocked register
accesses.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026040324-CVE-2026-31389-036b@gregkh/T
https://git.kernel.org/stable/c/0e23f50086da7d0b183dfeac26021acfcdee086bhttps://git.kernel.org/stable/c/23b51bad2eb8787aa74324cfccefb258515ae5bahttps://git.kernel.org/stable/c/6bbd385b30c7fb6c7ee0669e9ada91490938c051https://git.kernel.org/stable/c/80f3e8cd2b4ad355b2ad2024cf423f6d183404f7https://git.kernel.org/stable/c/8634e05b08ead636e926022f4a98416e13440df9https://git.kernel.org/stable/c/afe27c1f43aa57530011f419be6ddf71306565d2https://cert-portal.siemens.com/productcert/html/ssa-019113.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.html
2026-04-03
Published