CVE-2026-46228

MEDIUM

spi: ch341: fix devres lifetime

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: spi: ch341: fix devres lifetime USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes). Fix the controller and driver data lifetime so that they are released on driver unbind. Note that this also makes sure that the SPI controller is placed correctly under the USB interface in the device tree.

Scores

CVSS v3 5.5
EPSS 0.0012
EPSS Percentile 2.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-401
Status published
Products (12)
linux/Kernel 6.11.0 - 6.18.32linux
linux/Kernel 6.19.0 - 7.0.9linux
Linux/Linux < 6.11
Linux/Linux 6.11
Linux/Linux 6.18.32 - 6.18.*
Linux/Linux 7.0.9 - 7.0.*
Linux/Linux 7.1
Linux/Linux 7.1-rc1
Linux/Linux 8846739f52afa07e63395c80227dc544f54bd7b1 - 108a64b27a52f781c4f3751641e3dd65c7dd2fb5
Linux/Linux 8846739f52afa07e63395c80227dc544f54bd7b1 - 4422fc2411cbbdf5104a914e0596bb483faea254
... and 2 more
Published May 28, 2026
Tracked Since May 28, 2026