CVE-2026-31489: spi: meson-spicc: Fix double-put in remove path
In the Linux kernel, the following vulnerability has been resolved:
spi: meson-spicc: Fix double-put in remove path
mesonspiccprobe() registers the controller with devmspiregistercontroller(), so teardown already drops the controller reference via devm cleanup.
Calling spicontrollerput() again in mesonspiccremove() causes a double-put.
Affected Software
Event History
Frequently Asked Questions
What systems are exposed to this issue?
Systems running a Linux kernel with the meson-spicc SPI controller are affected. Microsoft azl3 kernel 6.6.141.1-1 is also listed as affected.
What access would an attacker need to exploit it?
The CVSS vector indicates local access and low privileges are required. No user interaction is required.
Is this caused by the SPI controller's normal removal path?
Yes. The issue occurs when meson_spicc_remove() calls spi_controller_put() even though devm_spi_register_controller() already arranges for the controller reference to be dropped during device-managed cleanup.