CVE-2021-46959: spi: Fix use-after-free with devm_spi_alloc_*
In the Linux kernel, the following vulnerability has been resolved:
spi: Fix use-after-free with devm_spi_alloc_*
We can't rely on the contents of the devres list during
spi_unregister_controller(), as the list is already torn down at the
time we perform devres_find() for devm_spi_release_controller. This
causes devices registered with devm_spi_alloc_{master,slave}() to be
mistakenly identified as legacy, non-devm managed devices and have their
reference counters decremented below 0.
------------[ cut here ]------------
WARNING: CPU: 1 PID: 660 at lib/refcount.c:28 refcount_warn_saturate+0x108/0x174
[<b0396f04>] (refcount_warn_saturate) from [<b03c56a4>] (kobject_put+0x90/0x98)
[<b03c5614>] (kobject_put) from [<b0447b4c>] (put_device+0x20/0x24)
r4:b6700140
[<b0447b2c>] (put_device) from [<b07515e8>] (devm_spi_release_controller+0x3c/0x40)
[<b07515ac>] (devm_spi_release_controller) from [<b045343c>] (release_nodes+0x84/0xc4)
r5:b6700180 r4:b6700100
[<b04533b8>] (release_nodes) from [<b0454160>] (devres_release_all+0x5c/0x60)
r8:b1638c54 r7:b117ad94 r6:b1638c10 r5:b117ad94 r4:b163dc10
[<b0454104>] (devres_release_all) from [<b044e41c>] (__device_release_driver+0x144/0x1ec)
r5:b117ad94 r4:b163dc10
[<b044e2d8>] (__device_release_driver) from [<b044f70c>] (device_driver_detach+0x84/0xa0)
r9:00000000 r8:00000000 r7:b117ad94 r6:b163dc54 r5:b1638c10 r4:b163dc10
[<b044f688>] (device_driver_detach) from [<b044d274>] (unbind_store+0xe4/0xf8)
Instead, determine the devm allocation state as a flag on the
controller which is guaranteed to be stable during cleanup.
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel bug in SPI device cleanup. Under specific driver removal or unbind paths, the kernel can mishandle reference counts and trigger a use-after-free condition. The sources do not provide CVSS, impact scoring, or active exploitation evidence.
Executive priority
Treat this as a patch-management item for Linux and embedded fleets, not an emergency based on current evidence. Prioritize systems with SPI hardware, custom kernels, or appliance firmware where kernel updates lag.
Technical view
During spi_unregister_controller(), devres state was queried after the devres list had already been torn down. devm_spi_alloc_{master,slave}() controllers could be misclassified as legacy controllers, causing extra put_device/kobject_put handling and refcount underflow. The fix stores devm allocation state in a stable controller flag.
Likely exposure
Exposure appears limited to Linux systems using affected kernel versions and SPI controller drivers that allocate controllers through devm_spi_alloc_master or devm_spi_alloc_slave, especially during driver detach, device unbind, or cleanup paths.
Exploitation context
The bundle marks KEV as false and gives no public evidence of exploitation. The provided trace shows a kernel warning during driver unbind, but the sources do not prove a practical attacker path or privilege requirement.
Researcher notes
The affected metadata is incomplete and includes version strings plus upstream stable commit references. No CWE, CVSS vector, or exploitability details are supplied. Analysis should focus on kernel version lineage, SPI controller usage, and whether the stable controller flag fix is present.
Mitigation direction
Update affected Linux kernels to vendor-supported builds containing the referenced stable fixes.
Check distribution or device vendor advisories for the exact fixed package version.
Prioritize embedded, appliance, and custom-kernel systems using SPI hardware or SPI controller drivers.
Avoid ad hoc driver changes unless validated against upstream stable patches.
Validation and detection
Inventory Linux kernel versions across servers, appliances, and embedded devices.
Identify systems with SPI controller drivers or custom kernel modules using SPI controller allocation.
Map running kernels to vendor fixed releases or the referenced stable commits.
Review kernel logs for refcount warnings during SPI driver detach or device unbind.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-46959 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.