{"id":"CVE-2026-93249","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: amlogic-spisg: Make sure clk_init_data is fully initialized\n\nThe clk_init_data structure contains several mutually-exclusive members\nfor different methods to speci…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: amlogic-spisg: Make sure clk_init_data is fully initialized\n\nThe clk_init_data structure contains several mutually-exclusive members\nfor different methods to speci…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= cef9991e04aed3305c61c392e880f6e01a0c2ea4 < bfce0f324efaa605e606cbb3f0bdb8fe5c910c11","Linux >= cef9991e04aed3305c61c392e880f6e01a0c2ea4 < 5969a3df8361a0e20379a308c2313d3e263123de","Linux >= cef9991e04aed3305c61c392e880f6e01a0c2ea4 < b2702908ee23ef31bfcf241a2e07ace0eb76bd71","Linux 6.17"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T16:17:21.070","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93249","references":[{"url":"https://git.kernel.org/stable/c/5969a3df8361a0e20379a308c2313d3e263123de","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2702908ee23ef31bfcf241a2e07ace0eb76bd71","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bfce0f324efaa605e606cbb3f0bdb8fe5c910c11","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T16:47:15.831Z","slug":"CVE-2026-93249","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nspi: amlogic-spisg: Make sure clk_init_data is fully initialized\n\nThe clk_init_data structure contains several mutually-exclusive members\nfor different methods to specify the possible parents of a clock,\nprompting drivers to initialize only the members they need.  However,\nnot initializing all members may cause subtle issues, which are only\nexposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is\nenabled.\n\naml_spisg_clk_init() fills in init.parent_data, and assumes that\ninit.parent_names is NULL.  However, the latter in uninitialized, and\nthus may cause a crash.\n\nMake sure all members are fully initialized, to fix such bugs, and to\navoid future breakage when converting drivers to a different method for\nspecifying the parents.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}