spi: cadence-quadspi: Implement refcount to handle unbind during busy
Summary
| CVE | CVE-2025-40005 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-10-20 16:15:37 UTC |
| Updated | 2026-06-01 17:16:36 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle unbind during busy driver support indirect read and indirect write operation with assumption no force device removal(unbind) operation. However force device removal(removal) is still available to root superuser. Unbinding driver during operation causes kernel crash. This changes ensure driver able to handle such operation for indirect read and indirect write by implementing refcount to track attached devices to the controller and gracefully wait and until attached devices remove operation completed before proceed with removal operation. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: NVD-CWE-noinfo
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected a314f6367787ee1d767df9a2120f17e4511144d0 8ce3ebbe5c718940b4e94f5c25f5720223f893f8 git | Not specified |
| CNA | Linux | Linux | affected a314f6367787ee1d767df9a2120f17e4511144d0 56787f4a75907ae99b5f5842b756fa68e2482f6d git | Not specified |
| CNA | Linux | Linux | affected a314f6367787ee1d767df9a2120f17e4511144d0 8df235f768cea7a5829cb02525622646eb0df5f5 git | Not specified |
| CNA | Linux | Linux | affected a314f6367787ee1d767df9a2120f17e4511144d0 65ed52200080eafce3eead05cf22ce01238defca git | Not specified |
| CNA | Linux | Linux | affected a314f6367787ee1d767df9a2120f17e4511144d0 b7ec8a2b094a33d0464958c2cbf75b8f229098b0 git | Not specified |
| CNA | Linux | Linux | affected a314f6367787ee1d767df9a2120f17e4511144d0 7446284023e8ef694fb392348185349c773eefb3 git | Not specified |
| CNA | Linux | Linux | affected 5.9 | Not specified |
| CNA | Linux | Linux | unaffected 5.9 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.209 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.167 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.125 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.78 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.16.10 6.16.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/b7ec8a2b094a33d0464958c2cbf75b8f229098b0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/65ed52200080eafce3eead05cf22ce01238defca | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/8df235f768cea7a5829cb02525622646eb0df5f5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/56787f4a75907ae99b5f5842b756fa68e2482f6d | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/7446284023e8ef694fb392348185349c773eefb3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/8ce3ebbe5c718940b4e94f5c25f5720223f893f8 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.