PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43460 Linux CVE debrief

CVE-2026-43460 is a Linux kernel double-free issue in the Rockchip SFC SPI controller driver. The problem comes from calling spi_unregister_controller() in remove() after registration was already handled by devm_spi_register_controller(), which can trigger a second free during device removal. The referenced fix changes probe() to use spi_register_controller() so controller teardown happens in the intended order before DMA buffer unmapping.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-20
Advisory published
2026-05-08
Advisory updated
2026-05-20

Who should care

Kernel maintainers, Linux distribution security teams, and operators of embedded/ARM systems that include the Rockchip SFC SPI flash controller should care most. NVD rates the issue as HIGH (CVSS 7.8) with local, low-privilege conditions, so systems that expose the affected kernel path should be prioritized for patching.

Technical summary

NVD classifies the weakness as CWE-415 (double free) and marks the vulnerability as analyzed. The supplied description states that the driver used devm_spi_register_controller() for registration, which performs automatic cleanup on device removal, while remove() also called spi_unregister_controller(); that overlap can lead to a double-free. The fix is to switch probe() to spi_register_controller() so the controller is unregistered explicitly and before DMA buffer unmapping. NVD lists affected Linux kernel ranges including 6.14 through before 6.18.19, 6.19 through before 6.19.9, and the early 7.0 release candidates rc1 through rc3.

Defensive priority

High. This is a kernel memory-safety issue with potential integrity and availability impact, and NVD’s CVSS vector indicates local access with low privileges is sufficient. Patch affected kernels and backport the upstream fix on any downstream branch that carries the Rockchip SFC driver.

Recommended defensive actions

  • Apply the upstream Linux kernel fix referenced by NVD for CVE-2026-43460.
  • If you maintain downstream kernels, backport the change that replaces devm_spi_register_controller() with spi_register_controller() in the Rockchip SFC driver.
  • Remove any redundant controller teardown path that could double-unregister the SPI controller during device removal.
  • Inventory systems using the Rockchip SFC SPI controller and confirm whether they run kernels in the affected version ranges listed by NVD.
  • After patching, validate that the affected driver path is present only in fixed builds and that your kernel package versions are updated across all fleets.

Evidence notes

The debrief is based only on the supplied CVE description and the official NVD record. NVD lists the weakness as CWE-415 and provides the CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The record also includes three kernel patch references, and the supplied description explicitly explains the double-free mechanism and the registration/unregistration fix. Affected version ranges are taken from the NVD CPE criteria in the source item.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43460 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43460

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43460 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43460

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/111e2863372c322e836e0c896f6dd9cf4ee08c71

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/85fb53351e6a3b921357a2178671e847a087e400

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b6051f2bdd4bd3dde85b68558edd3a6843489221

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.