CVE-2025-38081

medium

Description

In the Linux kernel, the following vulnerability has been resolved: spi-rockchip: Fix register out of bounds access Do not write native chip select stuff for GPIO chip selects. GPIOs can be numbered much higher than native CS. Also, it makes no sense.

References

https://git.kernel.org/stable/c/ace57bd1fb49d193edec5f6a1f255f48dd5fca90

https://git.kernel.org/stable/c/7a874e8b54ea21094f7fd2d428b164394c6cb316

https://git.kernel.org/stable/c/4a120221661fcecb253448d7b041a52d47f1d91f

https://git.kernel.org/stable/c/254e04ec799c1ff8c1e2bd08a57c6a849895d6ff

Details

Source: Mitre, NVD

Published: 2025-06-18

Updated: 2025-06-18

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00018