spi: fsl-cpm: Check length parity before switching to 16 bit mode

Summary

CVECVE-2025-68773
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-01-13 16:15:56 UTC
Updated2026-07-14 13:17:59 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: spi: fsl-cpm: Check length parity before switching to 16 bit mode Commit fc96ec826bce ("spi: fsl-cpm: Use 16 bit mode for large transfers with even size") failed to make sure that the size is really even before switching to 16 bit mode. Until recently the problem went unnoticed because kernfs uses a pre-allocated bounce buffer of size PAGE_SIZE for reading EEPROM. But commit 8ad6249c51d0 ("eeprom: at25: convert to spi-mem API") introduced an additional dynamically allocated bounce buffer whose size is exactly the size of the transfer, leading to a buffer overrun in the fsl-cpm driver when that size is odd. Add the missing length parity verification and remain in 8 bit mode when the length is not even.

Risk And Classification

EPSS: 0.001730000 probability, percentile 0.068840000 (date 2026-07-14)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 60afe299bb541a928ba39bcb4ae8d3e428d1c5a5 c8f1d35076b78df61ace737e41cc1f4b7b63236c git Not specified
CNA Linux Linux affected 4badd33929c05ed314794b95f1af1308f7222be8 9c34a4a2ead00979d203a8c16bea87f0ef5291d8 git Not specified
CNA Linux Linux affected 7f6738e003b364783f3019fdf6e7645bc8dd1643 837a23a11e0f734f096c7c7b0778d0e625e3dc87 git Not specified
CNA Linux Linux affected fc96ec826bced75cc6b9c07a4ac44bbf651337ab 3dd6d01384823e1bd8602873153d6fc4337ac4fe git Not specified
CNA Linux Linux affected fc96ec826bced75cc6b9c07a4ac44bbf651337ab 743cebcbd1b2609ec5057ab474979cef73d1b681 git Not specified
CNA Linux Linux affected fc96ec826bced75cc6b9c07a4ac44bbf651337ab be0b613198e6bfa104ad520397cab82ad3ec1771 git Not specified
CNA Linux Linux affected fc96ec826bced75cc6b9c07a4ac44bbf651337ab 1417927df8049a0194933861e9b098669a95c762 git Not specified
CNA Linux Linux affected 42c04316d9275ec267d36e5e9064cd56c9884148 git Not specified
CNA Linux Linux affected dc120f2d35b030390a2bc0f94dd5f37e900cae91 git Not specified
CNA Linux Linux affected b558275c1b040f0e5aa56c862241f9212b6118c3 git Not specified
CNA Linux Linux affected b9d9e8856f1c83e4277403f9b4c369b322ebcb12 git Not specified
CNA Linux Linux affected 36a6d0f66c874666caf4e8be155b1be30f6231be git Not specified
CNA Linux Linux affected 5.10.181 5.10.248 semver Not specified
CNA Linux Linux affected 5.15.114 5.15.198 semver Not specified
CNA Linux Linux affected 6.1.29 6.1.160 semver Not specified
CNA Linux Linux affected 4.14.316 4.15 semver Not specified
CNA Linux Linux affected 4.19.284 4.20 semver Not specified
CNA Linux Linux affected 5.4.244 5.5 semver Not specified
CNA Linux Linux affected 6.2.16 6.3 semver Not specified
CNA Linux Linux affected 6.3.3 6.4 semver Not specified
CNA Linux Linux affected 6.4 Not specified
CNA Linux Linux unaffected 6.4 semver Not specified
CNA Linux Linux unaffected 5.10.248 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.198 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.160 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.120 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.64 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.3 6.18.* semver Not specified
CNA Linux Linux unaffected 6.19 * original_commit_for_fix Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP affected V3.1.6 * custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP affected V3.1.6 * custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP affected V3.1.6 * custom Not specified
ADP Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP affected V3.1.6 * custom Not specified
ADP Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP affected V3.1.6 * custom Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/743cebcbd1b2609ec5057ab474979cef73d1b681 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/1417927df8049a0194933861e9b098669a95c762 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/c8f1d35076b78df61ace737e41cc1f4b7b63236c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/837a23a11e0f734f096c7c7b0778d0e625e3dc87 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
cert-portal.siemens.com/productcert/html/ssa-019113.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e cert-portal.siemens.com
git.kernel.org/stable/c/3dd6d01384823e1bd8602873153d6fc4337ac4fe 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/be0b613198e6bfa104ad520397cab82ad3ec1771 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/9c34a4a2ead00979d203a8c16bea87f0ef5291d8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report