SB2026011482 - Buffer overflow in Linux kernel spi driver
Published: January 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2025-68773)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the fsl_spi_prepare_message() function in drivers/spi/spi-fsl-spi.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1417927df8049a0194933861e9b098669a95c762
- https://git.kernel.org/stable/c/3dd6d01384823e1bd8602873153d6fc4337ac4fe
- https://git.kernel.org/stable/c/743cebcbd1b2609ec5057ab474979cef73d1b681
- https://git.kernel.org/stable/c/837a23a11e0f734f096c7c7b0778d0e625e3dc87
- https://git.kernel.org/stable/c/be0b613198e6bfa104ad520397cab82ad3ec1771