cbcvebase.
CVE-2025-37801
published 2025-05-08

CVE-2025-37801: In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Add check for the return value of…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.2th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: spi-imx: Add check for spi_imx_setupxfer() Add check for the return value of spi_imx_setupxfer(). spi_imx->rx and spi_imx->tx function pointer can be NULL when spi_imx_setupxfer() return error, and make NULL pointer dereference. Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 Call trace: 0x0 spi_imx_pio_transfer+0x50/0xd8 spi_imx_transfer_one+0x18c/0x858 spi_transfer_one_message+0x43c/0x790 __spi_pump_transfer_message+0x238/0x5d4 __spi_sync+0x2b0/0x454 spi_write_then_read+0x11c/0x200

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= 307c897db762d1e0feee9477276b08f6deca4a5b < 2fea0d6d7b5d27fbf55512d51851ba0a346ede522fea0d6d7b5d27fbf55512d51851ba0a346ede52
linuxlinux>= 307c897db762d1e0feee9477276b08f6deca4a5b < 2b4479eb462ecb39001b38dfb331fc6028dedac82b4479eb462ecb39001b38dfb331fc6028dedac8
linuxlinux>= 307c897db762d1e0feee9477276b08f6deca4a5b < 185d376875ea6fb4256b9dc97ee0b4d2b0fdd399185d376875ea6fb4256b9dc97ee0b4d2b0fdd399
linuxlinux>= 307c897db762d1e0feee9477276b08f6deca4a5b < 055ef73bb1afc3f783a9a13b496770a781964a07055ef73bb1afc3f783a9a13b496770a781964a07
linuxlinux>= 307c897db762d1e0feee9477276b08f6deca4a5b < 951a04ab3a2db4029debfa48d380ef834b93207e951a04ab3a2db4029debfa48d380ef834b93207e
linuxlinux_kernel< 6.1.1366.1.136
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.13 < 6.14.56.14.5
linuxlinux_kernel>= 6.2 < 6.6.896.6.89
linuxlinux_kernel>= 6.7 < 6.12.266.12.26
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux-aws

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.