OVERVIEW CVE-2026-31489 is a double-put reference counting vulnerability in the Linux kernel's Meson SPICC (SPI Controller) driver. The flaw occurs in the device removal path where spi_controller_put() is called redundantly, as the controller reference is already released through devm cleanup handlers during devm_spi_register_controller() registration. SEVERITY This vulnerability carries a CVSS score that is not yet available, limiting definitive severity classification. The EPSS score of 0.00018 indicates minimal exploitability probability relative to other CVEs. As a reference counting error in kernel driver code, the potential impact could include denial of service through memory corruption or system crashes on systems utilizing the Meson SPICC driver, though the actual attack surface is narrow and requires local access to trigger the remove path. EXPLOITATION STATUS There is no evidence of active exploitation of this vulnerability. It has not been added to CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is available. The vulnerability appears to be a logic error discovered through code analysis rather than through field exploitation. Community attention remains minimal, as reflected by the low FAUCET risk score of 20.0/100.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.14.244, < 4.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.19.203, < 4.20CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.4.140, < 5.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.10.58, < 5.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.13.10, < 5.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure FIPS) vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure) vulnerabilities
Jul 24, 2026Linux kernel (AWS) vulnerabilities
Jul 24, 2026Linux kernel (NVIDIA) vulnerabilities
Jul 23, 2026Linux kernel (Oracle) vulnerabilities
Jul 23, 2026Linux kernel vulnerabilities
Jul 23, 2026Linux kernel (NVIDIA Tegra) vulnerabilities
Jul 21, 2026Linux kernel vulnerabilities
Jul 21, 2026Linux kernel (GCP FIPS) vulnerabilities
Jul 21, 2026Linux kernel vulnerabilities
Jul 20, 2026spi: meson-spicc: Fix double-put in remove path
Apr 14, 2026