CVE-2025-37801

Updated: 2025-06-19 03:49:59.132454

Description:

In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Add check for the return value of spi_imx_setupxfer(). spi_imx->rx and spi_imx->tx function pointer can be NULL when spi_imx_setupxfer() return error, and make NULL pointer dereference. Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 Call trace: 0x0 spi_imx_pio_transfer+0x50/0xd8 spi_imx_transfer_one+0x18c/0x858 spi_transfer_one_message+0x43c/0x790 __spi_pump_transfer_message+0x238/0x5d4 __spi_sync+0x2b0/0x454 spi_write_then_read+0x11c/0x200


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-06-24 00:41:50
AlmaLinux 9.6 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-07-05 05:53:03
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-06-24 00:41:51
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-06-24 00:41:50
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-06-24 00:41:51
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-06-24 00:41:51
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2025-06-24 00:41:50
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-06-24 00:41:51
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2025-06-24 00:41:50
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2025-06-24 00:41:50
Total: 17