
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31389 is a use-after-free vulnerability in the Linux kernel's SPI (Serial Peripheral Interface) subsystem, specifically triggered during SPI controller registration failure. When per-cpu statistics allocation fails during controller registration, the driver fails to properly deregister from the driver core, resulting in use-after-free conditions on driver resources and unclocked register accesses. Affected kernel versions span multiple stable series: 6.0 through 6.1.x (before 6.1.167), 6.2–6.6.x (before 6.6.130), 6.7–6.12.x (before 6.12.78), 6.13–6.18.x (before 6.18.20), 6.19.x (before 6.19.10), and 7.0-rc1 through rc4. The vulnerability was published on April 3, 2026, and carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Feedly).
The root cause is classified as CWE-416 (Use After Free). During SPI controller registration, if the per-cpu statistics allocation step fails, the error-handling path does not call the driver core deregistration routine, leaving dangling references to already-freed driver resources. This allows subsequent code paths to access freed memory and perform unclocked hardware register accesses. The attack vector is local (AV:L), requiring low privileges (PR:L), and no user interaction, making it exploitable by any local user who can influence SPI controller registration — for example, by loading a malicious or crafted kernel module on systems permitting unprivileged module loading (GitHub Advisory, Feedly).
Successful exploitation can result in high confidentiality, integrity, and availability impact on the affected system. The use-after-free condition may lead to driver resource corruption, system instability or crashes, unclocked hardware register accesses, and potentially privilege escalation depending on the specific SPI controller implementation and system configuration. The vulnerability is confined to the local system scope but could serve as a stepping stone for privilege escalation in multi-tenant or container environments (Feedly).
Update the Linux kernel to one of the following patched versions: 6.1.167 or later (6.1.x series), 6.6.130 or later (6.6.x series), 6.12.78 or later (6.12.x series), 6.18.20 or later (6.18.x series), 6.19.10 or later (6.19.x series), or 7.0-rc5 or later. Upstream fixes are available in the Linux kernel stable repositories. For systems that cannot be updated immediately, restrict unprivileged access to SPI controller registration operations and monitor for SPI-related driver failures during boot or runtime. Distribution-specific updates are available from SUSE (SUSE-SU-2026:2217-1, SUSE-SU-2026:2238-1) and Amazon Linux 2023 (ALAS2023-2026-1594) (GitHub Advisory, SUSE Advisory, Amazon Linux).
The vulnerability was announced via the Linux kernel CVE announcement mailing list and subsequently tracked by Tenable (Nessus plugins 311335, 311340) and Qualys (detection IDs 762889, 762916, 762925). The Yocto Project security mailing list also discussed the issue across multiple messages. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."