Home

Description

In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: unregister ECC engine on probe error and device remove The on-host hardware ECC engine remains registered both when the spi_register_controller() function returns with an error and also on device removal. Change the qcom_spi_probe() function to unregister the engine on the error path, and add the missing unregistering call to qcom_spi_remove() to avoid possible use-after-free issues.

PUBLISHED Reserved 2025-04-16 | Published 2025-10-01 | Updated 2025-10-01 | Assigner Linux

Product status

Default status
unaffected

7304d1909080ef0c9da703500a97f46c98393fcd before e4de48e66af17547727bb2e4b1867952817edff7
affected

7304d1909080ef0c9da703500a97f46c98393fcd before 1991a458528588ff34e98b6365362560d208710f
affected

Default status
affected

6.15
affected

Any version before 6.15
unaffected

6.16.6
unaffected

6.17
unaffected

References

git.kernel.org/...c/e4de48e66af17547727bb2e4b1867952817edff7

git.kernel.org/...c/1991a458528588ff34e98b6365362560d208710f

cve.org (CVE-2025-39893)

nvd.nist.gov (CVE-2025-39893)

Download JSON