---
id: CVE-2026-93249
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  spi: amlogic-spisg: Make sure clk_init_data is fully initialized

  The clk_init_data structure contains several mutually-exclusive members
  for different methods to speci…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  spi: amlogic-spisg: Make sure clk_init_data is fully initialized

  The clk_init_data structure contains several mutually-exclusive members
  for different methods to speci…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= cef9991e04aed3305c61c392e880f6e01a0c2ea4 <
    bfce0f324efaa605e606cbb3f0bdb8fe5c910c11
  - >-
    Linux >= cef9991e04aed3305c61c392e880f6e01a0c2ea4 <
    5969a3df8361a0e20379a308c2313d3e263123de
  - >-
    Linux >= cef9991e04aed3305c61c392e880f6e01a0c2ea4 <
    b2702908ee23ef31bfcf241a2e07ace0eb76bd71
  - Linux 6.17
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T16:17:21.070'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93249'
references:
  - url: 'https://git.kernel.org/stable/c/5969a3df8361a0e20379a308c2313d3e263123de'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b2702908ee23ef31bfcf241a2e07ace0eb76bd71'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bfce0f324efaa605e606cbb3f0bdb8fe5c910c11'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T16:47:15.831Z'
epss: 0.00198
epssPercentile: 0.08547
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

spi: amlogic-spisg: Make sure clk_init_data is fully initialized

The clk_init_data structure contains several mutually-exclusive members
for different methods to specify the possible parents of a clock,
prompting drivers to initialize only the members they need.  However,
not initializing all members may cause subtle issues, which are only
exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is
enabled.

aml_spisg_clk_init() fills in init.parent_data, and assumes that
init.parent_names is NULL.  However, the latter in uninitialized, and
thus may cause a crash.

Make sure all members are fully initialized, to fix such bugs, and to
avoid future breakage when converting drivers to a different method for
specifying the parents.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
