cbcvebase.
CVE-2025-38081
published 2025-06-18

CVE-2025-38081: In the Linux kernel, the following vulnerability has been resolved: spi-rockchip: Fix register out of bounds access Do not write native chip select stuff for…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved: spi-rockchip: Fix register out of bounds access Do not write native chip select stuff for GPIO chip selects. GPIOs can be numbered much higher than native CS. Also, it makes no sense.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.32-1 (forky)linux 6.12.32-1 (forky)
linuxlinux
linuxlinux>= 736b81e075172f1e6cd7a8bc1a1374a2dee9e4dc < 4a120221661fcecb253448d7b041a52d47f1d91f4a120221661fcecb253448d7b041a52d47f1d91f
linuxlinux>= 736b81e075172f1e6cd7a8bc1a1374a2dee9e4dc < ace57bd1fb49d193edec5f6a1f255f48dd5fca90ace57bd1fb49d193edec5f6a1f255f48dd5fca90
linuxlinux>= 736b81e075172f1e6cd7a8bc1a1374a2dee9e4dc < 254e04ec799c1ff8c1e2bd08a57c6a849895d6ff254e04ec799c1ff8c1e2bd08a57c6a849895d6ff
linuxlinux>= 736b81e075172f1e6cd7a8bc1a1374a2dee9e4dc < 7a874e8b54ea21094f7fd2d428b164394c6cb3167a874e8b54ea21094f7fd2d428b164394c6cb316
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.14 < 6.6.936.6.93
linuxlinux_kernel>= 6.13 < 6.14.96.14.9
linuxlinux_kernel>= 6.7 < 6.12.316.12.31
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_redhat7.3HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.