Answer in brief
CVE-2026-80648 records a Unknown severity vulnerability in pinctrl: spacemit: fix NULL check in spacemit_pin_set_config. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a83c29e1d145cca5240952100acd1cd60f25fb5f <7a551951ebeb5b3f05bdb04a73d4593869c984c4 || >=a83c29e1d145cca5240952100acd1cd60f25fb5f <d3b53f0eda26e442ff97016ad4a0724db8fd3781 || >=a83c29e1d145cca5240952100acd1cd60f25fb5f <09c816e5c4d3a8d6d6e4b7537433e5e98505d934 | 7a551951ebeb5b3f05bdb04a73d4593869c984c4, d3b53f0eda26e442ff97016ad4a0724db8fd3781, 09c816e5c4d3a8d6d6e4b7537433e5e98505d934 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 28, 2026
In the Linux kernel, the following vulnerability has been resolved: pinctrl: spacemit: fix NULL check in spacemit_pin_set_config spacemit_pin_set_config() looks up the per-pin descriptor with spacemit_get_pin() then checks the wrong variable for failure: const struct spacemit_pin *spin = spacemit_get_pin(pctrl, pin); ... if (!pin) return -EINVAL; reg = spacemit_pin_to_reg(pctrl, spin->pin); pin is an unsigned int pin id, where 0 (GPIO_0 / gmac0_rxdv on K3) is a valid pin, so rejecting it here drops the PAD config write for the first pin of every group. On K3 Pico-ITX the GMAC RGMII group lists pin 0 as its first entry, so its drive-strength / bias configuration was silently ignored. The intended guard is against spacemit_get_pin() returning NULL when the pin id isn't in the SoC's pin table. Check spin instead, which both restores PAD setup for pin 0 and prevents a NULL deref on spin->pin.
Quoted source text, attributed separately from HOL analysis.