Unrated severityNVD Advisory· Published Jun 8, 2026
CVE-2026-46296
CVE-2026-46296
Description
In the Linux kernel, the following vulnerability has been resolved:
spi: s3c64xx: fix NULL-deref on driver unbind
A change moving DMA channel allocation from probe() back to s3c64xx_spi_prepare_transfer() failed to remove the corresponding deallocation from remove().
Drop the bogus DMA channel release from remove() to avoid triggering a NULL-pointer dereference on driver unbind.
This issue was flagged by Sashiko when reviewing a controller deregistration fix.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versions
>= 6.0.0, < 6.1.176+ 1 more
- (no CPE)range: >= 6.0.0, < 6.1.176
- (no CPE)range: < 7.0.12-1.1
Patches
Vulnerability mechanics
References
5- git.kernel.org/stable/c/1108b8722b9ff0cdd3e8aa18d98244fcd93b6760nvd
- git.kernel.org/stable/c/1b66f16a571a10ba8889ac471755c8af9c5b9266nvd
- git.kernel.org/stable/c/22788b1a8611380b141e09a8896702e32d164238nvd
- git.kernel.org/stable/c/323a258f4b1916b5a3098618e036e033b2f2317fnvd
- git.kernel.org/stable/c/45daacbead8a009844bd5dba6cfa731332184d17nvd
News mentions
1- Linux Kernel: 25 Vulnerabilities Disclosed in Single Batch on June 8, 2026Vypr Intelligence · Jun 8, 2026