PT-2025-40095 · Linux+2 · Linux Kernel+2

Published

2025-10-01

·

Updated

2025-10-01

·

CVE-2025-39921

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s spi subsystem, specifically within the microchip-core-qspi driver. A logic error introduced during a modification to the supports op callback function causes an invalid check of op->max freq during probe operations. This results in a division by zero when calculating baud rate val, leading to the failure of probe operations for attached memory devices. The issue stems from copying logic into mchp coreqspi supports op() that relies on a zero value for op->max freq during the probe phase.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2025-39921

Affected Products

Astra Linux
Linux Kernel
Microchip-Core-Qspi Driver