In the Linux kernel, the following vulnerability has been resolved:
spi: fix use-after-free on controller registration failure
Make sure to deregister from driver core also in the unlikely event that
per-cpu statistics allocation fails during controller registration to
avoid use-after-free (of driver resources) and unclocked register
accesses.
CVE-2026-31389
NONE
EPSS 0.03%
Updated Apr 07, 2026
Linux
https://git.kernel.org/stable/c/0e23f50086da7d0b183dfeac26021acfcdee086b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/23b51bad2eb8787aa74324cfccefb258515ae5ba
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/6bbd385b30c7fb6c7ee0669e9ada91490938c051
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/80f3e8cd2b4ad355b2ad2024cf423f6d183404f7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/8634e05b08ead636e926022f4a98416e13440df9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/afe27c1f43aa57530011f419be6ddf71306565d2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVE Details
CVE ID
CVE-2026-31389
Published Date
Apr 03, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.03%
Likelihood of exploitation in next 30 days
Percentile:
9.3th percentile (higher than 9.3% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory