PatchSiren cyber security CVE debrief
CVE-2026-23475 Linux CVE debrief
CVE-2026-23475 is a Linux kernel SPI subsystem vulnerability that can trigger a NULL-pointer dereference when sysfs statistics are accessed before per-controller statistics are allocated. NVD rates the issue as medium severity, with local low-privilege access leading to high availability impact. The published fix moves statistics allocation earlier in controller setup and ties its lifetime to the controller, closing the registration window that allowed the crash.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Linux kernel maintainers, distribution security teams, and operators running systems that expose SPI controller sysfs attributes should pay attention, especially where local users or sandboxed workloads may interact with the affected kernel.
Technical summary
According to the CVE description, the SPI controller per-CPU statistics were not allocated until after the controller had been registered with the driver core. That sequence left a window in which sysfs attribute access could dereference a NULL statistics pointer. The fix allocates statistics during controller allocation and ties cleanup to the controller lifecycle instead of relying on implicit devres behavior. NVD maps the weakness to CWE-476 and lists CVSS v3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a local, low-privilege denial-of-service condition.
Defensive priority
Moderate. This is a local availability issue rather than a remote code execution flaw, but it can still be disruptive on systems where untrusted local users or workloads exist. Patch priority should be high for kernels in the affected ranges listed by NVD and for products that expose the SPI sysfs interface.
Recommended defensive actions
- Apply the kernel fix referenced by the official stable patches and update to a release that includes the remediation.
- Prioritize upgrading Linux kernel versions in the affected NVD ranges: 6.0 before 6.1.167, 6.2 before 6.6.130, 6.7 before 6.12.78, 6.13 before 6.18.20, 6.19 before 6.19.10, and the listed 7.0 release candidates.
- Review systems where local users or containerized workloads may be able to access SPI-related sysfs attributes.
- After patching, verify that the SPI controller statistics allocation occurs during controller setup and that controller teardown cleans it up with the controller lifecycle.
- Track vendor backports if you rely on distribution kernels rather than upstream releases.
Evidence notes
The CVE record and NVD detail page identify the issue as analyzed, assign CWE-476, and provide the CVSS vector and affected version criteria. The kernel.org stable references are official patch links associated with the remediation. No exploit details are included here, and no facts beyond the supplied corpus and official links were used.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23475 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23475
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23475 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23475
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/118ce777d39f03cac99231196f820e4f998613a8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/378b295f67102eef78cf2c28105f60ae1dab5cc1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/80c5bd0dca1cc5526ae0f4b273ccd163ed4caa4e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/dee0774bbb2abb172e9069ce5ffef579b12b3ae9
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/df30056c78e8bead02d4be020199cabdbec0fef1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f13100b1f5f111989f0750540a795fdef47492af
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.