CVE-2025-40005
In the Linux kernel, the following vulnerability has been resolved:
spi: cadence-quadspi: Implement refcount to handle unbind during busy
driver support indirect read and indirect write operation with assumption no force device removal(unbind) operation. However force device removal(removal) is still available to root superuser.
Unbinding driver during operation causes kernel crash. This changes ensure driver able to handle such operation for indirect read and indirect write by implementing refcount to track attached devices to the controller and gracefully wait and until attached devices remove operation completed before proceed with removal operation.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- https://git.kernel.org/stable/c/56787f4a75907ae99b5f5842b756fa68e2482f6d
- https://git.kernel.org/stable/c/65ed52200080eafce3eead05cf22ce01238defca
- https://git.kernel.org/stable/c/7446284023e8ef694fb392348185349c773eefb3
- https://git.kernel.org/stable/c/8ce3ebbe5c718940b4e94f5c25f5720223f893f8
- https://git.kernel.org/stable/c/8df235f768cea7a5829cb02525622646eb0df5f5
- https://git.kernel.org/stable/c/b7ec8a2b094a33d0464958c2cbf75b8f229098b0
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-40005",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a314f6367787ee1d767df9a2120f17e4511144d0",
"lessThan": "8ce3ebbe5c718940b4e94f5c25f5720223f893f8",
"versionType": "git"
},
{
"status": "affected",
"version": "a314f6367787ee1d767df9a2120f17e4511144d0",
"lessThan": "56787f4a75907ae99b5f5842b756fa68e2482f6d",
"versionType": "git"
},
{
"status": "affected",
"version": "a314f6367787ee1d767df9a2120f17e4511144d0",
"lessThan": "8df235f768cea7a5829cb02525622646eb0df5f5",
"versionType": "git"
},
{
"status": "affected",
"version": "a314f6367787ee1d767df9a2120f17e4511144d0",
"lessThan": "65ed52200080eafce3eead05cf22ce01238defca",
"versionType": "git"
},
{
"status": "affected",
"version": "a314f6367787ee1d767df9a2120f17e4511144d0",
"lessThan": "b7ec8a2b094a33d0464958c2cbf75b8f229098b0",
"versionType": "git"
},
{
"status": "affected",
"version": "a314f6367787ee1d767df9a2120f17e4511144d0",
"lessThan": "7446284023e8ef694fb392348185349c773eefb3",
"versionType": "git"
}
],
"programFiles": [
"drivers/spi/spi-cadence-quadspi.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.9",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.125",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.16.10",
"versionType": "semver",
"lessThanOrEqual": "6.16.*"
},
{
"status": "unaffected",
"version": "6.17",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/spi/spi-cadence-quadspi.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-10-20T16:15:37.127",
"references": [
{
"url": "https://git.kernel.org/stable/c/56787f4a75907ae99b5f5842b756fa68e2482f6d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/65ed52200080eafce3eead05cf22ce01238defca",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7446284023e8ef694fb392348185349c773eefb3",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8ce3ebbe5c718940b4e94f5c25f5720223f893f8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8df235f768cea7a5829cb02525622646eb0df5f5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b7ec8a2b094a33d0464958c2cbf75b8f229098b0",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: cadence-quadspi: Implement refcount to handle unbind during busy\n\ndriver support indirect read and indirect write operation with\nassumption no force device removal(unbind) operation. However\nforce device removal(removal) is still available to root superuser.\n\nUnbinding driver during operation causes kernel crash. This changes\nensure driver able to handle such operation for indirect read and\nindirect write by implementing refcount to track attached devices\nto the controller and gracefully wait and until attached devices\nremove operation completed before proceed with removal operation."
}
],
"lastModified": "2026-06-17T09:21:06.400",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2F78819-3B3D-45F2-B2BC-445385A4FAE4",
"versionEndExcluding": "6.6.125",
"versionStartIncluding": "5.9"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "898CB0E7-69BE-48EB-A212-89F26E47CC47",
"versionEndExcluding": "6.16.10",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}