CVE-2026-23202: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer The curr_xfer field is read by the IRQ handler without holding the lock to check if a transfer is in progress. When clearing curr_xfer in the combined sequence transfer loop, protect it with the spinlock to prevent a race with the interrupt handler. Protect the curr_xfer clearing at the exit path of tegra_qspi_combined_seq_xfer() with the spinlock to prevent a race with the interrupt handler that reads this field. Without this protection, the IRQ handler could read a partially updated curr_xfer value, leading to NULL pointer dereference or use-after-free.

Affected products

  • Linux Linux Kernel: from 5.15.198, before 5.15.200 (fixed in 5.15.200); from 6.1.160, before 6.1.163 (fixed in 6.1.163); from 6.6.120, before 6.6.124 (fixed in 6.6.124); from 6.12.63, before 6.12.70 (fixed in 6.12.70); from 6.17.13, before 6.18 (fixed in 6.18); from 6.18.2, before 6.18.10 (fixed in 6.18.10); …

Published 2026-02-14. Last modified 2026-06-17.