Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: spi: imx: reconfigure for PIO when DMA cannot be started When spi_imx_can_dma()… (CVE-2026-72134)
Severity: lowType: VulnerabilityCVE-2026-72134
In the Linux kernel, the following vulnerability has been resolved: spi: imx: reconfigure for PIO when DMA cannot be started When spi_imx_can_dma() selects DMA, the ECSPI is configured for DMA: spi_imx_setupxfer() sets CTRL.SMC and clears dynamic_burst, and spi_imx_dma_transfer() programs the dynamic-burst BURST_LENGTH and the SDMA watermarks. If the DMA descriptor cannot be prepared (dmaengine_prep_slave_single() returns NULL), the transfer is failed with SPI_TRANS_FAIL_NO_START and falls back to PIO. The dynamic-burst DMA path uses its own bounce buffers instead of the SPI core's mapping, so xfer->{tx,rx}_sg_mapped are not set and the core's DMA->PIO retry is skipped; the driver falls back to PIO internally. But none of the DMA-mode configuration is undone, so the PIO transfer runs with CTRL.SMC set, the wrong burst length and dynamic_burst cleared, and the transferred data is corrupted. This is easily hit on i.MX8MP boards that describe ECSPI DMA in the device tree but run SDMA on ROM firmware (no external sdma-imx7d.bin): every ECSPI DMA prepare fails. An Infineon SLB9670 TPM on ECSPI1 then returns shifted TPM2_GetCapability data, is flagged "field failure mode", /dev/tpmrm0 is never created. Set controller->fallback before re-running spi_imx_setupxfer() so the ECSPI is reconfigured exactly like a normal PIO transfer. With controller->fallback set, spi_imx_setupxfer() sees spi_imx_can_dma() return false, so it clears spi_imx->usedma and reprograms the controller (clears CTRL.SMC, restores dynamic_burst and the PIO burst length). No explicit spi_imx->usedma = false is needed: setupxfer() already updates it from the can_dma() result.
AI Analysis
Technical Summary
The Linux kernel spi_imx driver configures the ECSPI controller for DMA transfers when spi_imx_can_dma() returns true. If DMA preparation fails (dmaengine_prep_slave_single() returns NULL), the driver falls back to PIO mode internally but does not undo the DMA-specific controller settings such as CTRL.SMC and dynamic burst configurations. This results in PIO transfers running with incorrect controller settings, causing data corruption. The issue is reproducible on i.MX8MP boards that describe ECSPI DMA in the device tree but lack the required SDMA firmware, causing all ECSPI DMA preparations to fail. This leads to corrupted TPM2_GetCapability responses and failure to create /dev/tpmrm0. The fix involves setting controller->fallback before re-running spi_imx_setupxfer(), ensuring the controller is reconfigured correctly for PIO mode by clearing DMA settings.
Potential Impact
Data corruption occurs during SPI transfers when DMA fallback to PIO mode happens without proper controller reconfiguration. This can cause TPM devices connected via ECSPI to malfunction, returning incorrect data and failing to initialize properly. The impact is limited to hardware platforms using the affected spi_imx driver with ECSPI controllers where DMA cannot start and fallback to PIO is triggered.
Mitigation Recommendations
A fix has been implemented in the Linux kernel spi_imx driver to correctly reconfigure the ECSPI controller for PIO mode when DMA cannot be started. Users should apply the official kernel update that includes this fix. Patch status is not explicitly stated in the provided data; therefore, check the vendor or Linux kernel advisory for the exact fixed version and remediation guidance.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: spi: imx: reconfigure for PIO when DMA cannot be started When spi_imx_can_dma()… (CVE-2026-72134)
Severity: low
Type: Vulnerability
CVE: CVE-2026-72134
In the Linux kernel, the following vulnerability has been resolved: spi: imx: reconfigure for PIO when DMA cannot be started When spi_imx_can_dma() selects DMA, the ECSPI is configured for DMA: spi_imx_setupxfer() sets CTRL.SMC and clears dynamic_burst, and spi_imx_dma_transfer() programs the dynamic-burst BURST_LENGTH and the SDMA watermarks. If the DMA descriptor cannot be prepared (dmaengine_prep_slave_single() returns NULL), the transfer is failed with SPI_TRANS_FAIL_NO_START and falls back to PIO. The dynamic-burst DMA path uses its own bounce buffers instead of the SPI core's mapping, so xfer->{tx,rx}_sg_mapped are not set and the core's DMA->PIO retry is skipped; the driver falls back to PIO internally. But none of the DMA-mode configuration is undone, so the PIO transfer runs with CTRL.SMC set, the wrong burst length and dynamic_burst cleared, and the transferred data is corrupted. This is easily hit on i.MX8MP boards that describe ECSPI DMA in the device tree but run SDMA on ROM firmware (no external sdma-imx7d.bin): every ECSPI DMA prepare fails. An Infineon SLB9670 TPM on ECSPI1 then returns shifted TPM2_GetCapability data, is flagged "field failure mode", /dev/tpmrm0 is never created. Set controller->fallback before re-running spi_imx_setupxfer() so the ECSPI is reconfigured exactly like a normal PIO transfer. With controller->fallback set, spi_imx_setupxfer() sees spi_imx_can_dma() return false, so it clears spi_imx->usedma and reprograms the controller (clears CTRL.SMC, restores dynamic_burst and the PIO burst length). No explicit spi_imx->usedma = false is needed: setupxfer() already updates it from the can_dma() result.
Technical Summary
The Linux kernel spi_imx driver configures the ECSPI controller for DMA transfers when spi_imx_can_dma() returns true. If DMA preparation fails (dmaengine_prep_slave_single() returns NULL), the driver falls back to PIO mode internally but does not undo the DMA-specific controller settings such as CTRL.SMC and dynamic burst configurations. This results in PIO transfers running with incorrect controller settings, causing data corruption. The issue is reproducible on i.MX8MP boards that describe ECSPI DMA in the device tree but lack the required SDMA firmware, causing all ECSPI DMA preparations to fail. This leads to corrupted TPM2_GetCapability responses and failure to create /dev/tpmrm0. The fix involves setting controller->fallback before re-running spi_imx_setupxfer(), ensuring the controller is reconfigured correctly for PIO mode by clearing DMA settings.
Potential Impact
Data corruption occurs during SPI transfers when DMA fallback to PIO mode happens without proper controller reconfiguration. This can cause TPM devices connected via ECSPI to malfunction, returning incorrect data and failing to initialize properly. The impact is limited to hardware platforms using the affected spi_imx driver with ECSPI controllers where DMA cannot start and fallback to PIO is triggered.
Mitigation Recommendations
A fix has been implemented in the Linux kernel spi_imx driver to correctly reconfigure the ECSPI controller for PIO mode when DMA cannot be started. Users should apply the official kernel update that includes this fix. Patch status is not explicitly stated in the provided data; therefore, check the vendor or Linux kernel advisory for the exact fixed version and remediation guidance.
Source: GCVE Database
Published: 08/15/2026
EPSS 0.2%top 95%
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: spi: imx: reconfigure for PIO when DMA cannot be started When spi_imx_can_dma()… (CVE-2026-72134)
In the Linux kernel, the following vulnerability has been resolved: spi: imx: reconfigure for PIO when DMA cannot be started When spi_imx_can_dma() selects DMA, the ECSPI is configured for DMA: spi_imx_setupxfer() sets CTRL.SMC and clears dynamic_burst, and spi_imx_dma_transfer() programs the dynamic-burst BURST_LENGTH and the SDMA watermarks. If the DMA descriptor cannot be prepared (dmaengine_prep_slave_single() returns NULL), the transfer is failed with SPI_TRANS_FAIL_NO_START and falls back to PIO. The dynamic-burst DMA path uses its own bounce buffers instead of the SPI core's mapping, so xfer->{tx,rx}_sg_mapped are not set and the core's DMA->PIO retry is skipped; the driver falls back to PIO internally. But none of the DMA-mode configuration is undone, so the PIO transfer runs with CTRL.SMC set, the wrong burst length and dynamic_burst cleared, and the transferred data is corrupted. This is easily hit on i.MX8MP boards that describe ECSPI DMA in the device tree but run SDMA on ROM firmware (no external sdma-imx7d.bin): every ECSPI DMA prepare fails. An Infineon SLB9670 TPM on ECSPI1 then returns shifted TPM2_GetCapability data, is flagged "field failure mode", /dev/tpmrm0 is never created. Set controller->fallback before re-running spi_imx_setupxfer() so the ECSPI is reconfigured exactly like a normal PIO transfer. With controller->fallback set, spi_imx_setupxfer() sees spi_imx_can_dma() return false, so it clears spi_imx->usedma and reprograms the controller (clears CTRL.SMC, restores dynamic_burst and the PIO burst length). No explicit spi_imx->usedma = false is needed: setupxfer() already updates it from the can_dma() result.
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
AILast updated: 08/15/2026, 16:55:55 UTC
Technical Analysis
The Linux kernel spi_imx driver configures the ECSPI controller for DMA transfers when spi_imx_can_dma() returns true. If DMA preparation fails (dmaengine_prep_slave_single() returns NULL), the driver falls back to PIO mode internally but does not undo the DMA-specific controller settings such as CTRL.SMC and dynamic burst configurations. This results in PIO transfers running with incorrect controller settings, causing data corruption. The issue is reproducible on i.MX8MP boards that describe ECSPI DMA in the device tree but lack the required SDMA firmware, causing all ECSPI DMA preparations to fail. This leads to corrupted TPM2_GetCapability responses and failure to create /dev/tpmrm0. The fix involves setting controller->fallback before re-running spi_imx_setupxfer(), ensuring the controller is reconfigured correctly for PIO mode by clearing DMA settings.
Potential Impact
Data corruption occurs during SPI transfers when DMA fallback to PIO mode happens without proper controller reconfiguration. This can cause TPM devices connected via ECSPI to malfunction, returning incorrect data and failing to initialize properly. The impact is limited to hardware platforms using the affected spi_imx driver with ECSPI controllers where DMA cannot start and fallback to PIO is triggered.
Mitigation Recommendations
A fix has been implemented in the Linux kernel spi_imx driver to correctly reconfigure the ECSPI controller for PIO mode when DMA cannot be started. Users should apply the official kernel update that includes this fix. Patch status is not explicitly stated in the provided data; therefore, check the vendor or Linux kernel advisory for the exact fixed version and remediation guidance.
Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro
Technical Details
Gcve Source
db.gcve.eu
Osv Id
GHSA-pv8g-5qg3-q63w
Osv Schema Version
1.4.0
Aliases
["CVE-2026-72134"]
Threat ID: 6a808b75bf8831d5394ffae4
Added to database: 08/15/2026, 15:53:25 UTC
Last enriched: 08/15/2026, 16:55:55 UTC
Last updated: 09/30/2026, 06:54:40 UTC
Views: 28
Community Reviews
0 reviews
Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Sort by
Loading community insights…
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.