cbcvebase.
CVE-2025-68773
published 2026-01-13

CVE-2025-68773: In the Linux kernel, the following vulnerability has been resolved: spi: fsl-cpm: Check length parity before switching to 16 bit mode Commit fc96ec826bce…

PriorityP422medium6.4
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: spi: fsl-cpm: Check length parity before switching to 16 bit mode Commit fc96ec826bce ("spi: fsl-cpm: Use 16 bit mode for large transfers with even size") failed to make sure that the size is really even before switching to 16 bit mode. Until recently the problem went unnoticed because kernfs uses a pre-allocated bounce buffer of size PAGE_SIZE for reading EEPROM. But commit 8ad6249c51d0 ("eeprom: at25: convert to spi-mem API") introduced an additional dynamically allocated bounce buffer whose size is exactly the size of the transfer, leading to a buffer overrun in the fsl-cpm driver when that size is odd. Add the missing length parity verification and remain in 8 bit mode when the length is not even.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.316 < 4.154.15
linuxlinux>= 4.19.284 < 4.204.20
linuxlinux>= 4badd33929c05ed314794b95f1af1308f7222be8 < 9c34a4a2ead00979d203a8c16bea87f0ef5291d89c34a4a2ead00979d203a8c16bea87f0ef5291d8
linuxlinux>= 5.10.181 < 5.10.2485.10.248
linuxlinux>= 5.15.114 < 5.15.1985.15.198
linuxlinux>= 5.4.244 < 5.55.5
linuxlinux>= 6.1.29 < 6.1.1606.1.160
linuxlinux>= 6.2.16 < 6.36.3
linuxlinux>= 6.3.3 < 6.46.4
linuxlinux>= 60afe299bb541a928ba39bcb4ae8d3e428d1c5a5 < c8f1d35076b78df61ace737e41cc1f4b7b63236cc8f1d35076b78df61ace737e41cc1f4b7b63236c
linuxlinux>= 7f6738e003b364783f3019fdf6e7645bc8dd1643 < 837a23a11e0f734f096c7c7b0778d0e625e3dc87837a23a11e0f734f096c7c7b0778d0e625e3dc87
linuxlinux>= fc96ec826bced75cc6b9c07a4ac44bbf651337ab < 3dd6d01384823e1bd8602873153d6fc4337ac4fe3dd6d01384823e1bd8602873153d6fc4337ac4fe
linuxlinux>= fc96ec826bced75cc6b9c07a4ac44bbf651337ab < 743cebcbd1b2609ec5057ab474979cef73d1b681743cebcbd1b2609ec5057ab474979cef73d1b681
linuxlinux>= fc96ec826bced75cc6b9c07a4ac44bbf651337ab < be0b613198e6bfa104ad520397cab82ad3ec1771be0b613198e6bfa104ad520397cab82ad3ec1771
linuxlinux>= fc96ec826bced75cc6b9c07a4ac44bbf651337ab < 1417927df8049a0194933861e9b098669a95c7621417927df8049a0194933861e9b098669a95c762
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.