PT-2024-7180 · Linux+8 · Linux Kernel+8

Han Xu

·

Published

2024-09-11

·

Updated

2026-05-05

·

CVE-2024-46853

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.11.0-rc5-gc7b0e37c8434
Description The vulnerability is related to an out-of-bounds issue in the nxp fspi exec op function when writing data that is not 4 byte aligned to TX FIFO. This can be reproduced by writing 3 bytes of data to a NOR chip using the dd command. The issue is caused by a slab-out-of-bounds error in the nxp fspi exec op function, which is part of the SPI driver. The vulnerability can potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the spi: nxp-fspi out-of-bounds bug. As a temporary workaround, consider disabling the nxp fspi exec op function until a patch is available. However, this may have unintended consequences and should be carefully evaluated before implementation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2024-13979
ALT-PU-2024-14046
AZL-49945
AZL-49983
BDU:2024-08519
CVE-2024-46853
DLA-4008-1
DLA-4075-1
DSA-5782-1
INFSA-2025_6966
OESA-2024-2321
OESA-2024-2322
OESA-2024-2324
OESA-2024-2325
OPENSUSE-SU-2024_3984-1
OPENSUSE-SU-2024_3986-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4376-1
RHSA-2025:6966
RHSA-2025_6966
SUSE-SU-2024:3559-1
SUSE-SU-2024:3566-1
SUSE-SU-2024:3591-1
SUSE-SU-2024:3984-1
SUSE-SU-2024:3986-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7166-1
USN-7166-2
USN-7166-3
USN-7166-4
USN-7186-1
USN-7186-2
USN-7194-1
USN-7196-1
USN-7293-1
USN-7294-1
USN-7294-2
USN-7294-3
USN-7294-4
USN-7295-1
USN-7393-1
USN-7401-1
USN-7413-1
USN-7539-1
USN-7540-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu