CVE-2026-31489: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: spi: meson-spicc: Fix double-put in remove path meson_spicc_probe() registers the controller with devm_spi_register_controller(), so teardown already drops the controller reference via devm cleanup. Calling spi_controller_put() again in meson_spicc_remove() causes a double-put.
Affected products
- Linux Linux Kernel: from 4.14.244, before 4.15 (fixed in 4.15); from 4.19.203, before 4.20 (fixed in 4.20); from 5.4.140, before 5.5 (fixed in 5.5); from 5.10.58, before 5.11 (fixed in 5.11); from 5.13.10, before 5.14 (fixed in 5.14); from 5.14.1, before 6.12.80 (fixed in 6.12.80); …
Published 2026-04-22. Last modified 2026-06-19.