PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23475 Linux CVE debrief

CVE-2026-23475 is a Linux kernel SPI subsystem vulnerability that can trigger a NULL-pointer dereference when sysfs statistics are accessed before per-controller statistics are allocated. NVD rates the issue as medium severity, with local low-privilege access leading to high availability impact. The published fix moves statistics allocation earlier in controller setup and ties its lifetime to the controller, closing the registration window that allowed the crash.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-28
Advisory published
2026-07-14
Advisory updated
2026-07-28

Who should care

Linux kernel maintainers, distribution security teams, and operators running systems that expose SPI controller sysfs attributes should pay attention, especially where local users or sandboxed workloads may interact with the affected kernel.

Technical summary

According to the CVE description, the SPI controller per-CPU statistics were not allocated until after the controller had been registered with the driver core. That sequence left a window in which sysfs attribute access could dereference a NULL statistics pointer. The fix allocates statistics during controller allocation and ties cleanup to the controller lifecycle instead of relying on implicit devres behavior. NVD maps the weakness to CWE-476 and lists CVSS v3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a local, low-privilege denial-of-service condition.

Defensive priority

Moderate. This is a local availability issue rather than a remote code execution flaw, but it can still be disruptive on systems where untrusted local users or workloads exist. Patch priority should be high for kernels in the affected ranges listed by NVD and for products that expose the SPI sysfs interface.

Recommended defensive actions

  • Apply the kernel fix referenced by the official stable patches and update to a release that includes the remediation.
  • Prioritize upgrading Linux kernel versions in the affected NVD ranges: 6.0 before 6.1.167, 6.2 before 6.6.130, 6.7 before 6.12.78, 6.13 before 6.18.20, 6.19 before 6.19.10, and the listed 7.0 release candidates.
  • Review systems where local users or containerized workloads may be able to access SPI-related sysfs attributes.
  • After patching, verify that the SPI controller statistics allocation occurs during controller setup and that controller teardown cleans it up with the controller lifecycle.
  • Track vendor backports if you rely on distribution kernels rather than upstream releases.

Evidence notes

The CVE record and NVD detail page identify the issue as analyzed, assign CWE-476, and provide the CVSS vector and affected version criteria. The kernel.org stable references are official patch links associated with the remediation. No exploit details are included here, and no facts beyond the supplied corpus and official links were used.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23475 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23475

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23475 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23475

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/118ce777d39f03cac99231196f820e4f998613a8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/378b295f67102eef78cf2c28105f60ae1dab5cc1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/80c5bd0dca1cc5526ae0f4b273ccd163ed4caa4e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/dee0774bbb2abb172e9069ce5ffef579b12b3ae9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/df30056c78e8bead02d4be020199cabdbec0fef1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f13100b1f5f111989f0750540a795fdef47492af

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.