In the Linux kernel, the following vulnerability has been resolved:
spi: bcm2835: bcm2835_spi_handle_err(): fix NULL pointer deref for non DMA transfers
In case a IRQ based transfer times out the bcm2835_spi_handle_err() function is called. Since commit 1513ceee70f2 ("spi: bcm2835: Drop dma_pending flag") the TX and RX DMA transfers are unconditionally canceled, leading to NULL pointer derefs if ctlr->dma_tx or ctlr->dma_rx are not set.
Fix the NULL pointer deref by checking that ctlr->dma_tx and ctlr->dma_rx are valid pointers before accessing them.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Ubuntu | — | Upgrade linux-hwe-5.4Upgrade linux-awsUpgrade linux-gcpUpgrade linux-raspi-5.4Upgrade linux-aws-fipsUpgrade linux-iotUpgrade linux-realtimeUpgrade linuxUpgrade linux-ibm-5.4Upgrade linux-lowlatency-hwe-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-azureUpgrade linux-bluefieldUpgrade linux-gcp-5.4Upgrade linux-azure-5.4Upgrade linux-hwe-5.15Upgrade linux-gcp-fipsUpgrade linux-kvmUpgrade linux-gkeUpgrade linux-lowlatencyUpgrade linux-aws-5.4Upgrade linux-fipsUpgrade linux-azure-fipsUpgrade linux-gcp-5.15Upgrade linux-oracleUpgrade linux-nvidiaUpgrade linux-raspiUpgrade linux-oracle-5.15Upgrade linux-ibmUpgrade linux-aws-5.15Upgrade linux-riscv-5.15Upgrade linux-azure-5.15Upgrade linux-gkeopUpgrade linux-oracle-5.4Upgrade linux-intel-iotg | Mar 3, 2025 | Feb 26, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub