{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72133","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.907Z","datePublished":"2026-08-15T05:53:08.833Z","dateUpdated":"2026-08-17T05:40:43.316Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:40:43.316Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: uniphier: Fix completion initialization order before devm_request_irq()\n\nThe driver calls devm_request_irq() before initializing the completion\nused by the interrupt handler. Because the interrupt may occur immediately\nafter devm_request_irq(), the handler may execute before init_completion().\n\nThis may result in calling complete() on an uninitialized completion,\ncausing undefined behavior. This has been observed with KASAN.\n\nFix this by initializing the completion before registering the IRQ."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in uniphier_spi_probe() on Socionext UniPhier embedded SoCs; uniphier_spi_handler() runs during platform driver initialization at boot/module load, not via network protocols, remote packets, or runtime SPI syscalls/ioctls.\nAC:L - Commit and reporter confirm the SPI controller IRQ may assert immediately after devm_request_irq(); stale or pending SSI status on warm reboot can invoke complete() on uninitialized xfer_done without attacker luck.\nPR:N - uniphier_spi_probe() has no credential or capability checks before devm_request_irq(); on affected UniPhier boards the vulnerable probe sequence runs automatically during kernel boot without the attacker holding Linux privileges.\nUI:N - No victim action is required; a pending SPI controller interrupt during driver probe at boot or reboot can trigger the uninitialized complete() path without opening /dev/spidev*, mounting filesystems, or other user operations.\nS:U - Impact is kernel panic from uninitialized completion/spinlock handling within the host kernel; this is not a VM escape, hypervisor bypass, IOMMU violation, or sandbox boundary crossing on embedded UniPhier systems.\nC:H - complete() takes an uninitialized wait.lock and swake_up_locked() walks a zeroed task_list, causing KASAN wild-memory-access and invalid kernel memory reads beyond a strictly bounded NULL fault.\nI:H - Calling complete() on an uninitialized completion corrupts spinlock/wait-queue metadata in uniphier_spi_priv; KASAN-reported undefined behavior in IRQ context can corrupt adjacent kzalloc slab data and enable further kernel control primitives.\nA:H - KASAN wild-memory-access and NULL list dereference in uniphier_spi_handler() during probe cause kernel oops/panic on affected UniPhier embedded devices, denying all system availability until reboot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/spi/spi-uniphier.c"],"versions":[{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"b9fcf0db433d79648ace74bc2b8b88f91e306304","status":"affected","versionType":"git"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"82a5746c4c9e94f6f816ec7edea6ddc24417c6a5","status":"affected","versionType":"git"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"f4bb0a91f7badd6d15ac8d783a1169d9e1e95c17","status":"affected","versionType":"git"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"49f6705d80b5e6175d8435d9c72b66bd516a8e89","status":"affected","versionType":"git"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"8b5798ce0007874c14611b8ee4ce6c749855260e","status":"affected","versionType":"git"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"d44b828eb551bd59ba9f22457825cc3db3a39fc1","status":"affected","versionType":"git"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"077a7bc1c32d3da9670c5e282ea3e5ac8a94be59","status":"affected","versionType":"git"},{"version":"5ba155a4d4cc8e4cdd3db6df7d03271a3bd91177","lessThan":"f3ad1c87d8201e54b66bd6072442f0b5d5a308ee","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/spi/spi-uniphier.c"],"versions":[{"version":"4.19","status":"affected"},{"version":"0","lessThan":"4.19","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b9fcf0db433d79648ace74bc2b8b88f91e306304"},{"url":"https://git.kernel.org/stable/c/82a5746c4c9e94f6f816ec7edea6ddc24417c6a5"},{"url":"https://git.kernel.org/stable/c/f4bb0a91f7badd6d15ac8d783a1169d9e1e95c17"},{"url":"https://git.kernel.org/stable/c/49f6705d80b5e6175d8435d9c72b66bd516a8e89"},{"url":"https://git.kernel.org/stable/c/8b5798ce0007874c14611b8ee4ce6c749855260e"},{"url":"https://git.kernel.org/stable/c/d44b828eb551bd59ba9f22457825cc3db3a39fc1"},{"url":"https://git.kernel.org/stable/c/077a7bc1c32d3da9670c5e282ea3e5ac8a94be59"},{"url":"https://git.kernel.org/stable/c/f3ad1c87d8201e54b66bd6072442f0b5d5a308ee"}],"title":"spi: uniphier: Fix completion initialization order before devm_request_irq()","x_generator":{"engine":"bippy-1.2.0"}}}}