CVE-2025-68746

Linux Kernel 5.12.0-6.18.1 - Use-After-Free in SPI Tegra210-Quad Driver

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Fix timeout handling When the CPU that the QSPI interrupt handler runs on (typically CPU 0) is excessively busy, it can lead to rare cases of the IRQ thread not running before the transfer timeout is reached. While handling the timeouts, any pending transfers are cleaned up and the message that they correspond to is marked as failed, which leaves the curr_xfer field pointing at stale memory. To avoid this, clear curr_xfer to NULL upon timeout and check for this condition when the IRQ thread is finally run. While at it, also make sure to clear interrupts on failure so that new interrupts can be run. A better, more involved, fix would move the interrupt clearing into a hard IRQ handler. Ideally we would also want to signal that the IRQ thread no longer needs to be run after the timeout is hit to avoid the extra check for a valid transfer.

Scores

EPSS 0.0004
EPSS Percentile 13.2%

Details

Status published
Products (22)
linux/Kernel 5.12.0 - 5.15.198linux
linux/Kernel 5.16.0 - 6.1.160linux
linux/Kernel 6.13.0 - 6.17.13linux
linux/Kernel 6.18.0 - 6.18.2linux
linux/Kernel 6.2.0 - 6.6.120linux
linux/Kernel 6.7.0 - 6.12.63linux
Linux/Linux < 5.12
Linux/Linux 5.12
Linux/Linux 5.15.198 - 5.15.*
Linux/Linux 6.1.160 - 6.1.*
... and 12 more
Published Dec 24, 2025
Tracked Since Feb 18, 2026