VYPR
Unrated severityNVD Advisory· Published Feb 4, 2026· Updated Feb 9, 2026

spi: spi-sprd-adi: Fix double free in probe error path

CVE-2026-23068

Description

In the Linux kernel, the following vulnerability has been resolved:

spi: spi-sprd-adi: Fix double free in probe error path

The driver currently uses spi_alloc_host() to allocate the controller but registers it using devm_spi_register_controller().

If devm_register_restart_handler() fails, the code jumps to the put_ctlr label and calls spi_controller_put(). However, since the controller was registered via a devm function, the device core will automatically call spi_controller_put() again when the probe fails. This results in a double-free of the spi_controller structure.

Fix this by switching to devm_spi_alloc_host() and removing the manual spi_controller_put() call.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

71

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.