VYPR
Medium severity5.5NVD Advisory· Published Jul 1, 2026· Updated Jul 23, 2026

CVE-2026-53344

CVE-2026-53344

Description

In the Linux kernel, the following vulnerability has been resolved:

pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init

Regmap initialization triggers regcache_maple_populate() which attempts SPI read to populate cache. SPI read requires mcp->dev and mcp->addr to be set, without them, NULL pointer dereference occurs during probe.

Move initialization before mcp23s08_spi_regmap_init() call.

Affected products

10
  • Linux/Kernel9 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.19,<7.0.13
    • cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc6:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc7:*:*:*:*:*:*
    • (no CPE)
  • osv-coords
    Range: >= 6.19.0, < 7.0.13

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.