From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 097573A9624 for ; Wed, 3 Jun 2026 15:51:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780501906; cv=none; b=pR3z3C+JrBUPzdlVuyRFQpWPFrZYuOmrAuLVKbbwiprAXX9c4ElB7e7BBhiL9YUucTPsVog/89m121EWP8nY+NtAxU7z8zYXHu27HVfqd4RPo/OPBIeu8rN+le0DStWIxrxuK3IQcK/lKdPrm6jrvbV7VAwQGVEUiDgysypPt4Y= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780501906; c=relaxed/simple; bh=/ptdZESuh6xIfLHbw+pS6ep/CuCsDDlKXqay+79XKIc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=TMoLbuGPjwBRl7bkeC2CXNEyztT+7QNNGQtmY8tKDz7Vw6ICc5+sfVNSPpvqibTc2YFpeKioFDxlLGEG9wTWq6ASZ3UcdyV3rpGkM0ZMY492q97yRi2R/UIlziikbDuk0DI0TT78UH1PMY1qsLvCqUCe90xe3pYSvcETmDNjyLU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=YJazYJ9x; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="YJazYJ9x" Received: by smtp.kernel.org (Postfix) with ESMTPSA id F3D001F00893; Wed, 3 Jun 2026 15:51:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1780501904; bh=lxD+n++dKaAdXDq4aZCDOEqzszW2cSAeiFQmnXx/l9I=; h=From:To:Cc:Subject:Date:Reply-To; b=YJazYJ9xecmqVmF46B2VYZN4uFpPXmkw1BAR4+cEQUUDCb0yFL1XwK/NFkcYzAEny tN4U0/tAJ6KrkZjQYHH2T448g9swNEasa7L6ccHKggEK92Q25ka48V6XYmgdG3Bqs0 uBH0Wfap3oKk0ZQV9eKu6JC8rJpJF4+b2ynNsbmc= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-46269: pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree Date: Wed, 3 Jun 2026 17:49:58 +0200 Message-ID: <2026060338-CVE-2026-46269-3ec0@gregkh> X-Mailer: git-send-email 2.54.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2892; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=1729jTAft5CaE7NNXWBC/5wHh6XZ5y2ZMhGCqx5Jwlg=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkKvkIrZfOcShgt1B4dMCywEf6heVa7fp+AlNaEZyV73 7+vE8joiGVhEGRikBVTZPmyjefo/opDil6Gtqdh5rAygQxh4OIUgImoZjDM97jEmTrh/vtVDXfE 046ZJn5Q9fv5mWGexl7TjBVn1ObKqDvGZEh+uC9109sfAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree When probing the k230 pinctrl driver, the kernel triggers a NULL pointer dereference. The crash trace showed: [ 0.732084] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000068 [ 0.740737] ... [ 0.776296] epc : k230_pinctrl_probe+0x1be/0x4fc In k230_pinctrl_parse_functions(), we attempt to retrieve the device pointer via info->pctl_dev->dev, but info->pctl_dev is only initialized after k230_pinctrl_parse_dt() completes. At the time of DT parsing, info->pctl_dev is still NULL, leading to the invalid dereference of info->pctl_dev->dev. Use the already available device pointer from platform_device instead of accessing through uninitialized pctl_dev. The Linux kernel CVE team has assigned CVE-2026-46269 to this issue. Affected and fixed versions =========================== Issue introduced in 6.17 with commit d94a32ac688f953dc9a9f12b5b4139ecad841bbb and fixed in 6.18.14 with commit 3c7d637bfc3dfbd6471c68bd767f7eb8b5b09eba Issue introduced in 6.17 with commit d94a32ac688f953dc9a9f12b5b4139ecad841bbb and fixed in 6.19.4 with commit 1d0d361f4dbc2bb2003594f84e4b101fc6b508c0 Issue introduced in 6.17 with commit d94a32ac688f953dc9a9f12b5b4139ecad841bbb and fixed in 7.0 with commit d8c128fb6c2277d95f3f6a4ce28b82c8370031f6 Issue introduced in 6.15.10 with commit 02c1deb1bff2b6d242e29a51e56107495979a2b8 Issue introduced in 6.16.1 with commit 0ec03251d01494ef207089b5bd626becfd05fd86 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-46269 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/pinctrl/pinctrl-k230.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/3c7d637bfc3dfbd6471c68bd767f7eb8b5b09eba https://git.kernel.org/stable/c/1d0d361f4dbc2bb2003594f84e4b101fc6b508c0 https://git.kernel.org/stable/c/d8c128fb6c2277d95f3f6a4ce28b82c8370031f6