cbcvebase.
CVE-2025-40005
published 2025-10-20

CVE-2025-40005: In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle unbind during busy driver support…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.3th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle unbind during busy driver support indirect read and indirect write operation with assumption no force device removal(unbind) operation. However force device removal(removal) is still available to root superuser. Unbinding driver during operation causes kernel crash. This changes ensure driver able to handle such operation for indirect read and indirect write by implementing refcount to track attached devices to the controller and gracefully wait and until attached devices remove operation completed before proceed with removal operation.

Affected

64 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.10-1 (forky)linux 6.16.10-1 (forky)
linuxlinux
linuxlinux>= a314f6367787ee1d767df9a2120f17e4511144d0 < 8ce3ebbe5c718940b4e94f5c25f5720223f893f88ce3ebbe5c718940b4e94f5c25f5720223f893f8
linuxlinux>= a314f6367787ee1d767df9a2120f17e4511144d0 < 56787f4a75907ae99b5f5842b756fa68e2482f6d56787f4a75907ae99b5f5842b756fa68e2482f6d
linuxlinux>= a314f6367787ee1d767df9a2120f17e4511144d0 < 8df235f768cea7a5829cb02525622646eb0df5f58df235f768cea7a5829cb02525622646eb0df5f5
linuxlinux>= a314f6367787ee1d767df9a2120f17e4511144d0 < 65ed52200080eafce3eead05cf22ce01238defca65ed52200080eafce3eead05cf22ce01238defca
linuxlinux>= a314f6367787ee1d767df9a2120f17e4511144d0 < b7ec8a2b094a33d0464958c2cbf75b8f229098b0b7ec8a2b094a33d0464958c2cbf75b8f229098b0
linuxlinux>= a314f6367787ee1d767df9a2120f17e4511144d0 < 7446284023e8ef694fb392348185349c773eefb37446284023e8ef694fb392348185349c773eefb3
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.16.10-16.16.10-1
linuxlinux_kernel>= 5.9 < 6.6.1256.6.125
linuxlinux_kernel>= 6.7 < 6.16.106.16.10
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_msrc6.6MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.