
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68773 is a buffer overrun vulnerability in the Linux kernel's SPI FSL-CPM (Freescale CPM) driver. The driver failed to verify that transfer sizes are even before switching to 16-bit mode, causing out-of-bounds writes when odd-sized transfers occur. It affects Linux kernel versions from the introduction of commit fc96ec826bce through multiple stable branches, with fixes available in versions 6.1.160, 6.6.120, 6.12.64, 6.18.3, and 6.19-rc2. The vulnerability was published on January 13, 2026, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Feedly).
The root cause is a missing input validation check (CWE class: improper input validation / out-of-bounds write) in the fsl-cpm SPI driver. Commit fc96ec826bce introduced 16-bit transfer mode for large even-sized transfers but omitted the parity check. The vulnerability was latent until commit 8ad6249c51d0 ("eeprom: at25: convert to spi-mem API") changed the at25 EEPROM driver to use dynamically allocated bounce buffers sized exactly to the transfer length rather than a fixed PAGE_SIZE buffer — when an odd-sized transfer is issued, the 16-bit mode operation writes one byte beyond the allocated buffer boundary. Exploitation requires local access with low privileges and the presence of the fsl-cpm SPI driver with an attached at25 EEPROM device (Red Hat CVE, Feedly).
Successful exploitation causes a kernel buffer overrun that can crash the system, resulting in a denial of service. The vulnerability has no confidentiality or integrity impact — only availability is affected, as the overrun can destabilize or panic the kernel. The scope is limited to the local system running the affected fsl-cpm SPI driver, with no known path to lateral movement or data exfiltration (Feedly, Red Hat CVE).
Apply the patched kernel versions for your maintained branch: Linux 6.1.160, 6.6.120, 6.12.64, 6.18.3, or 6.19-rc2 and later. Microsoft has released a patch for the Azure Linux 3 kernel (azl3_kernel_6.6.119.3-3). Debian, Ubuntu (USN-8177-1, USN-8179-1, USN-8183-1, USN-8184-1, USN-8185-1, USN-8203-1, USN-8245-1, USN-8257-1, USN-8258-1, USN-8260-1, USN-8265-1), and SUSE have also issued advisories with updated packages. If immediate patching is not possible, restrict access to SPI device interfaces and monitor for unexpected kernel crashes related to SPI or EEPROM operations (Red Hat CVE, Feedly, Ubuntu USN-8177-1).
Red Hat has published a CVE record and is tracking the vulnerability. Debian issued security advisories (DSA-6126-1 and DLA-4475-1) covering this CVE in updated kernel packages. Ubuntu issued multiple security notices (USN-8177-1 through USN-8265-1 series) addressing this and related kernel vulnerabilities. No notable independent researcher commentary or significant social media discussion has been identified for this vulnerability (Red Hat CVE, Ubuntu USN-8177-1, Debian LTS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."