In the Linux kernel, the following vulnerability has been resolved:
spi: ch341: fix out-of-bounds memory access in ch341_transfer_one
Discovered by Atuin - Automated Vulnerability Discovery Engine.
The 'len' variable is calculated as 'min(32, trans->len + 1)', which includes the 1-byte command header.
When copying data from 'trans->tx_buf' to 'ch341->tx_buf + 1', using 'len' as the length is incorrect because:
1. It causes an out-of-bounds read from 'trans->tx_buf' (which has size 'trans->len', i.e., 'len - 1' in this context). 2. It can cause an out-of-bounds write to 'ch341->tx_buf' if 'len' is CH341_PACKET_LENGTH (32). Writing 32 bytes to ch341->tx_buf + 1 overflows the buffer.
Fix this by copying 'len - 1' bytes.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Ubuntu | — | Upgrade linux-image-6.17.0-1009-gcpUpgrade linux-image-oem-24.04bUpgrade linux-image-oracle-6.17Upgrade linux-image-awsUpgrade linux-image-oracleUpgrade linux-image-virtualUpgrade linux-image-6.17.0-1017-oemUpgrade linux-image-realtimeUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-oem-24.04aUpgrade linux-image-gcpUpgrade linux-image-6.17.0-1010-raspiUpgrade linux-image-oem-6.17Upgrade linux-image-aws-6.17Upgrade linux-image-aws-64kUpgrade linux-image-gcp-6.17Upgrade linux-image-oem-24.04dUpgrade linux-image-oem-24.04Upgrade linux-image-6.17.0-1009-gcp-64kUpgrade linux-image-6.17.0-1009-aws-64kUpgrade linux-image-6.17.0-1009-oracle-64kUpgrade linux-image-raspi-6.17Upgrade linux-image-generic-6.17Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oracle-64kUpgrade linux-image-oem-24.04cUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-raspiUpgrade linux-image-6.17.0-19-generic-64kUpgrade linux-image-virtual-6.17Upgrade linux-image-realtime-6.17Upgrade linux-image-oracle-64k-6.17Upgrade linux-image-generic-64kUpgrade linux-image-6.17.0-1008-realtimeUpgrade linux-image-azure-6.17Upgrade linux-image-aws-64k-6.17Upgrade linux-image-generic-64k-6.17Upgrade linux-image-6.17.0-19-genericUpgrade linux-image-gcp-64kUpgrade linux-image-genericUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-6.17.0-1010-azureUpgrade linux-image-6.17.0-1009-awsUpgrade linux-image-6.17.0-1009-oracleUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-azure | Mar 17, 2026 | Dec 24, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 15, 2026 | Dec 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub