We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-22067

spi: cadence: Fix out-of-bounds array access in cdns_mrvl_xspi_setup_clock()



Description

In the Linux kernel, the following vulnerability has been resolved: spi: cadence: Fix out-of-bounds array access in cdns_mrvl_xspi_setup_clock() If requested_clk > 128, cdns_mrvl_xspi_setup_clock() iterates over the entire cdns_mrvl_xspi_clk_div_list array without breaking out early, causing 'i' to go beyond the array bounds. Fix that by stopping the loop when it gets to the last entry, clamping the clock to the minimum 6.25 MHz. Fixes the following warning with an UBSAN kernel: vmlinux.o: warning: objtool: cdns_mrvl_xspi_setup_clock: unexpected end of section .text.cdns_mrvl_xspi_setup_clock

Reserved 2024-12-29 | Published 2025-04-16 | Updated 2025-04-16 | Assigner Linux

Product status

Default status
unaffected

26d34fdc49712ddbd42b11102f5d9d78a0f42097 before e50781bf7accc75883cb8a6a9921fb4e2fa8cca4
affected

26d34fdc49712ddbd42b11102f5d9d78a0f42097 before c1fb84e274cb6a2bce6ba5e65116c06e0b3ab275
affected

26d34fdc49712ddbd42b11102f5d9d78a0f42097 before 645f1813fe0dc96381c36b834131e643b798fd73
affected

26d34fdc49712ddbd42b11102f5d9d78a0f42097 before 7ba0847fa1c22e7801cebfe5f7b75aee4fae317e
affected

Default status
affected

6.12
affected

Any version before 6.12
unaffected

6.12.23
unaffected

6.13.11
unaffected

6.14.2
unaffected

6.15-rc1
unaffected

References

git.kernel.org/...c/e50781bf7accc75883cb8a6a9921fb4e2fa8cca4

git.kernel.org/...c/c1fb84e274cb6a2bce6ba5e65116c06e0b3ab275

git.kernel.org/...c/645f1813fe0dc96381c36b834131e643b798fd73

git.kernel.org/...c/7ba0847fa1c22e7801cebfe5f7b75aee4fae317e

cve.org (CVE-2025-22067)

nvd.nist.gov (CVE-2025-22067)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-22067

Support options

Helpdesk Chat, Email, Knowledgebase