CVE-2022-50190 Information

Description

In the Linux kernel the following vulnerability has been resolved:

spi: Fix simplification of devm_spi_register_controller

This reverts commit 59ebbe40fb51 (\spi: simplify devm_spi_register_controller).

If devm_add_action() fails in devm_add_action_or_reset() devm_spi_unregister() will be called it decreases the refcount of ‘ctlr->dev’ to 0 then it will cause uaf in the drivers that calling spi_put_controller() in error path.

Reference

https://git.kernel.org/stable/c/34bab623ebfc08398499e463396b81abb4abe01e https://git.kernel.org/stable/c/3c6bd448442b6c3f6843ac70d57201a13478dd47 https://git.kernel.org/stable/c/43cc5a0afe4184a7fafe1eba32b5a11bb69c9ce0 https://git.kernel.org/stable/c/445fb9c19cf45bd9472fd9babaa31c5e6c7d2720

CNNVD-202506-2478 (Published: 2025-06-18)

Share on: