CVE-2026-31489 PUBLISHED

spi: meson-spicc: Fix double-put in remove path

Assigner: Linux
Reserved: 09.03.2026 Published: 22.04.2026 Updated: 22.04.2026

In the Linux kernel, the following vulnerability has been resolved:

spi: meson-spicc: Fix double-put in remove path

meson_spicc_probe() registers the controller with devm_spi_register_controller(), so teardown already drops the controller reference via devm cleanup.

Calling spi_controller_put() again in meson_spicc_remove() causes a double-put.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 8311ee2164c5cd1b63a601ea366f540eae89f10e to 40ad0334c17b23d8b66b1082ad1478a6202e90e2 (excl.)
  • affected from 8311ee2164c5cd1b63a601ea366f540eae89f10e to da06a104f0486355073ff0d1bcb1fcbebb7080d6 (excl.)
  • affected from 8311ee2164c5cd1b63a601ea366f540eae89f10e to 9b812ceb75a6260c17c91db4b9e74ead8cfa06f5 (excl.)
  • affected from 8311ee2164c5cd1b63a601ea366f540eae89f10e to 63542bb402b7013171c9f621c28b609eda4dbf1f (excl.)
  • Version ff056817560d72363b463ddac27822dc8c121280 is affected
  • Version 683b47d0ebb10ba0d272604b09686e023d10d40c is affected
  • Version a5bf7ef13ebf6adf62a69ab3542d4fc0564c082e is affected
  • Version 05565b469358a9a03034f7f712d83590a9f125a4 is affected
  • Version f2ca988aba4eaad1319e80eb1316a4ba5dbd6897 is affected
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.14 is affected
  • unaffected from 0 to 5.14 (excl.)
  • unaffected from 6.12.80 to 6.12.* (incl.)
  • unaffected from 6.18.21 to 6.18.* (incl.)
  • unaffected from 6.19.11 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References