CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-37842: spi: fsl-qspi: use devm function instead of driver remove

Description

In the Linux kernel, the following vulnerability has been resolved:

spi: fsl-qspi: use devm function instead of driver remove

Driver use devm APIs to manage clk/irq/resources and register the spi
controller, but the legacy remove function will be called first during
device detach and trigger kernel panic. Drop the remove function and use
devm_add_action_or_reset() for driver cleanup to ensure the release
sequence.

Trigger kernel panic on i.MX8MQ by
echo 30bb0000.spi >/sys/bus/platform/drivers/fsl-quadspi/unbind

Classification

CVE ID: CVE-2025-37842

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 4.25% (scored less or equal to compared to others)

EPSS Date: 2025-06-07 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-37842
https://git.kernel.org/stable/c/439688dbe82baa10d4430dc3252bb5ef1183a171
https://git.kernel.org/stable/c/f9bfb3a5f6f616f3eb7665c8ff3bcb9760ae33c8
https://git.kernel.org/stable/c/40369bfe717e96e26650eeecfa5a6363563df6e4

Timeline