{"api_version":"1","generated_at":"2026-07-23T14:47:08+00:00","cve":"CVE-2025-40005","urls":{"html":"https://cve.report/CVE-2025-40005","api":"https://cve.report/api/cve/CVE-2025-40005.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-40005","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-40005"},"summary":{"title":"spi: cadence-quadspi: Implement refcount to handle unbind during busy","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: cadence-quadspi: Implement refcount to handle unbind during busy\n\ndriver support indirect read and indirect write operation with\nassumption no force device removal(unbind) operation. However\nforce device removal(removal) is still available to root superuser.\n\nUnbinding driver during operation causes kernel crash. This changes\nensure driver able to handle such operation for indirect read and\nindirect write by implementing refcount to track attached devices\nto the controller and gracefully wait and until attached devices\nremove operation completed before proceed with removal operation.","state":"PUBLISHED","assigner":"Linux","published_at":"2025-10-20 16:15:37","updated_at":"2026-06-01 17:16:36"},"problem_types":["NVD-CWE-noinfo"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}}],"references":[{"url":"https://git.kernel.org/stable/c/b7ec8a2b094a33d0464958c2cbf75b8f229098b0","name":"https://git.kernel.org/stable/c/b7ec8a2b094a33d0464958c2cbf75b8f229098b0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/65ed52200080eafce3eead05cf22ce01238defca","name":"https://git.kernel.org/stable/c/65ed52200080eafce3eead05cf22ce01238defca","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8df235f768cea7a5829cb02525622646eb0df5f5","name":"https://git.kernel.org/stable/c/8df235f768cea7a5829cb02525622646eb0df5f5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/56787f4a75907ae99b5f5842b756fa68e2482f6d","name":"https://git.kernel.org/stable/c/56787f4a75907ae99b5f5842b756fa68e2482f6d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7446284023e8ef694fb392348185349c773eefb3","name":"https://git.kernel.org/stable/c/7446284023e8ef694fb392348185349c773eefb3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8ce3ebbe5c718940b4e94f5c25f5720223f893f8","name":"https://git.kernel.org/stable/c/8ce3ebbe5c718940b4e94f5c25f5720223f893f8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-40005","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-40005","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a314f6367787ee1d767df9a2120f17e4511144d0 8ce3ebbe5c718940b4e94f5c25f5720223f893f8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a314f6367787ee1d767df9a2120f17e4511144d0 56787f4a75907ae99b5f5842b756fa68e2482f6d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a314f6367787ee1d767df9a2120f17e4511144d0 8df235f768cea7a5829cb02525622646eb0df5f5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a314f6367787ee1d767df9a2120f17e4511144d0 65ed52200080eafce3eead05cf22ce01238defca git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a314f6367787ee1d767df9a2120f17e4511144d0 b7ec8a2b094a33d0464958c2cbf75b8f229098b0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a314f6367787ee1d767df9a2120f17e4511144d0 7446284023e8ef694fb392348185349c773eefb3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.9","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.209 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.167 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.125 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.78 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.16.10 6.16.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.17 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2025","cve_id":"40005","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/spi/spi-cadence-quadspi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"8ce3ebbe5c718940b4e94f5c25f5720223f893f8","status":"affected","version":"a314f6367787ee1d767df9a2120f17e4511144d0","versionType":"git"},{"lessThan":"56787f4a75907ae99b5f5842b756fa68e2482f6d","status":"affected","version":"a314f6367787ee1d767df9a2120f17e4511144d0","versionType":"git"},{"lessThan":"8df235f768cea7a5829cb02525622646eb0df5f5","status":"affected","version":"a314f6367787ee1d767df9a2120f17e4511144d0","versionType":"git"},{"lessThan":"65ed52200080eafce3eead05cf22ce01238defca","status":"affected","version":"a314f6367787ee1d767df9a2120f17e4511144d0","versionType":"git"},{"lessThan":"b7ec8a2b094a33d0464958c2cbf75b8f229098b0","status":"affected","version":"a314f6367787ee1d767df9a2120f17e4511144d0","versionType":"git"},{"lessThan":"7446284023e8ef694fb392348185349c773eefb3","status":"affected","version":"a314f6367787ee1d767df9a2120f17e4511144d0","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/spi/spi-cadence-quadspi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.9"},{"lessThan":"5.9","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.209","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.167","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.125","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.78","versionType":"semver"},{"lessThanOrEqual":"6.16.*","status":"unaffected","version":"6.16.10","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"6.17","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.209","versionStartIncluding":"5.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.167","versionStartIncluding":"5.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.125","versionStartIncluding":"5.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.78","versionStartIncluding":"5.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.16.10","versionStartIncluding":"5.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.17","versionStartIncluding":"5.9","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: cadence-quadspi: Implement refcount to handle unbind during busy\n\ndriver support indirect read and indirect write operation with\nassumption no force device removal(unbind) operation. However\nforce device removal(removal) is still available to root superuser.\n\nUnbinding driver during operation causes kernel crash. This changes\nensure driver able to handle such operation for indirect read and\nindirect write by implementing refcount to track attached devices\nto the controller and gracefully wait and until attached devices\nremove operation completed before proceed with removal operation."}],"providerMetadata":{"dateUpdated":"2026-06-01T16:05:33.466Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/8ce3ebbe5c718940b4e94f5c25f5720223f893f8"},{"url":"https://git.kernel.org/stable/c/56787f4a75907ae99b5f5842b756fa68e2482f6d"},{"url":"https://git.kernel.org/stable/c/8df235f768cea7a5829cb02525622646eb0df5f5"},{"url":"https://git.kernel.org/stable/c/65ed52200080eafce3eead05cf22ce01238defca"},{"url":"https://git.kernel.org/stable/c/b7ec8a2b094a33d0464958c2cbf75b8f229098b0"},{"url":"https://git.kernel.org/stable/c/7446284023e8ef694fb392348185349c773eefb3"}],"title":"spi: cadence-quadspi: Implement refcount to handle unbind during busy","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2025-40005","datePublished":"2025-10-20T15:26:52.315Z","dateReserved":"2025-04-16T07:20:57.151Z","dateUpdated":"2026-06-01T16:05:33.466Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-10-20 16:15:37","lastModifiedDate":"2026-06-01 17:16:36","problem_types":["NVD-CWE-noinfo"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.9","versionEndExcluding":"6.6.125","matchCriteriaId":"A2F78819-3B3D-45F2-B2BC-445385A4FAE4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.16.10","matchCriteriaId":"898CB0E7-69BE-48EB-A212-89F26E47CC47"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*","matchCriteriaId":"327D22EF-390B-454C-BD31-2ED23C998A1C"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*","matchCriteriaId":"C730CD9A-D969-4A8E-9522-162AAF7C0EE9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*","matchCriteriaId":"39982C4B-716E-4B2F-8196-FA301F47807D"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*","matchCriteriaId":"340BEEA9-D70D-4290-B502-FBB1032353B1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"40005","Ordinal":"1","Title":"spi: cadence-quadspi: Implement refcount to handle unbind during","CVE":"CVE-2025-40005","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"40005","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nspi: cadence-quadspi: Implement refcount to handle unbind during busy\n\ndriver support indirect read and indirect write operation with\nassumption no force device removal(unbind) operation. However\nforce device removal(removal) is still available to root superuser.\n\nUnbinding driver during operation causes kernel crash. This changes\nensure driver able to handle such operation for indirect read and\nindirect write by implementing refcount to track attached devices\nto the controller and gracefully wait and until attached devices\nremove operation completed before proceed with removal operation.","Type":"Description","Title":"spi: cadence-quadspi: Implement refcount to handle unbind during"}]}}}