In the Linux kernel, the following vulnerability has been resolved:
spi: tegra20-slink: fix UAF in tegra_slink_remove()
After calling spi_unregister_master(), the refcount of master will be decrease to 0, and it will be freed in spi_controller_release(), the device data also will be freed, so it will lead a UAF when using 'tspi'. To fix this, get the master before unregister and put it when finish using it.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jun 20, 2025 | Jun 20, 2025 |
| Dell Powerstore Dsa2025429 | — | Upgrade Dell PowerStoreOS to the latest version | Dec 3, 2025 | Dec 2, 2025 |
| Dell Powerstore Dsa2026039 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Jan 6, 2026 |
| Ubuntu | — | Upgrade linux-gcpUpgrade linux-awsUpgrade linuxUpgrade linux-hwe-5.15Upgrade linux-aws-5.15Upgrade linux-azureUpgrade linux-lowlatency-hwe-5.15Upgrade linux-gkeopUpgrade linux-intel-iotgUpgrade linux-intel-iotg-5.15Upgrade linux-gkeUpgrade linux-riscv-5.15Upgrade linux-realtimeUpgrade linux-oracleUpgrade linux-raspiUpgrade linux-ibmUpgrade linux-kvmUpgrade linux-gcp-5.15Upgrade linux-azure-5.15Upgrade linux-oracle-5.15Upgrade linux-nvidiaUpgrade linux-lowlatency | Jun 26, 2025 | Jun 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub