CVE-2026-45996: spi: imx: fix use-after-free on unbind

Published May 27, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

spi: imx: fix use-after-free on unbind

The SPI subsystem frees the controller and any subsystem allocated driver data as part of deregistration (unless the allocation is device managed).

Take another reference before deregistering the controller so that the driver data is not freed until the driver is done with it.

Affected Software

6 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=5.19<6.6.140
Linux Linux kernel>=6.7<6.12.86
Linux Linux kernel>=6.13<6.18.27
Linux Linux kernel>=6.19<7.0.4
Microsoft azl3 kernel 6.6.139.1-1<6.6.141.1-1
6.6.141.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.6.141.1-1

Event History

May 27, 2026
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
Description
Data Sourced
via NVD·02:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 28, 2026
Data Sourced
via Microsoft·08:08 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:08 AM
Affected Software
Updated
via Microsoft·08:08 AM
DescriptionSeverity

Frequently Asked Questions

1

What level of access is required to exploit this issue?

The vulnerability is rated with local attack vector, low attack complexity, low privileges required, and no user interaction. It is therefore relevant to systems where a low-privileged local user can interact with the affected kernel driver.

2

What is the expected security impact?

The CVSS vector indicates high impact to availability, with no reported confidentiality or integrity impact. Exploitation may cause a denial of service through the use-after-free condition.

3

When does the vulnerable condition occur?

The condition occurs during unbind and controller deregistration in the i.MX SPI driver. The SPI subsystem can free the controller and driver data during deregistration while the driver still uses that data.

4

Which products are identified as affected?

The affected software list identifies the Linux kernel and Microsoft azl3 kernel 6.6.139.1-1. The issue is associated with the i.MX SPI driver.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203