CVE-2026-46203
Awaiting Analysis Awaiting Analysis - Queue
SPI Controller Unclocked Access in Linux Kernel

Publication date: 2026-05-28

Last updated on: 2026-05-28

Assigner: kernel.org

Description
In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: fix unclocked access on unbind Make sure that the controller is runtime resumed before disabling it during driver unbind to avoid an unclocked register access. This issue was flagged by Sashiko when reviewing a controller deregistration fix.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-28
Last Modified
2026-05-28
Generated
2026-05-28
AI Q&A
2026-05-28
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
cadence quadspi *
linux linux_kernel *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Linux kernel's cadence-quadspi driver. It involves an unclocked register access that occurs during the driver unbind process. Specifically, the controller must be runtime resumed before it is disabled during unbind to prevent accessing registers without a clock signal.


How can this vulnerability impact me? :

If the controller is accessed without being properly clocked, it could lead to undefined behavior or system instability. This might cause crashes or malfunctions in systems relying on the cadence-quadspi controller, potentially affecting device reliability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart