CVE-2025-21845

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 12, 2025
Updated: Mar 13, 2025

Summary

CVE-2025-21845: A vulnerability in the Linux kernel's sst driver of the SPI-NOR subsystem has been identified and resolved. The issue, introduced by commit '18bcb4aa54ea', causes only one byte to be written instead of the intended number during the write operation, resulting in a kernel crash. The issue can be found in the function 'sst_nor_write_data', and its impact is demonstrated in the call trace. The correct number of bytes should be written as passed to 'sst_nor_write_data'.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share