A vulnerability described as critical has been identified in Linux Kernel up to 7.0-rc4. The impacted element is an unknown function of the component spi. The manipulation results in null pointer dereference. This vulnerability is cataloged as CVE-2026-23475. The attack must originate from the local network. Upgrading the affected component is recommended.
| Vendor | Product | Versions |
|---|---|---|
| linux | linux kernel | 6598b91b5ac32bc756d7c3000a31f775d4ead1c4, 6598b91b5ac32bc756d7c3000a31f775d4ead1c4, 6598b91b5ac32bc756d7c3000a31f775d4ead1c4, 6598b91b5ac32bc756d7c3000a31f775d4ead1c4, 6598b91b5ac32bc756d7c3000a31f775d4ead1c4, 6598b91b5ac32bc756d7c3000a31f775d4ead1c4, 6.0, 6.1.167, 6.6.130, 6.12.78, 6.18.20, 6.19.10, 7.0-rc5 |
Updated severity to CRITICAL, added CWE-476, and corrected exploit availability to false.
Added CVE-2026-23475, updated affected versions, and provided detailed patch information.
Initial creation