In the Linux kernel, the following vulnerability has been resolved:
spi: cs42l43: Property entry should be a null-terminated array
The software node does not specify a count of property entries, so the array must be null-terminated.
When unterminated, this can lead to a fault in the downstream cs35l56 amplifier driver, because the node parse walks off the end of the array into unknown memory.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/cc431b3424123d84bcd7afd4de150b33f117a8ef/cves/2025/38xxx/CVE-2025-38573.json"
}[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ffcfd071eec7973e58c4ffff7da4cb0e9ca7b667",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-38573-6bc99428",
"target": {
"file": "drivers/spi/spi-cs42l43.c"
},
"digest": {
"line_hashes": [
"85696440487582173616552622727841444794",
"6160248363928552774586277454783071127",
"80611815404687391292209848339969580556",
"225044949120024921019853608363219948774"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9f0035ae38d2571f5ddedc829d74492013caa625",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-38573-70e7d1e4",
"target": {
"file": "drivers/spi/spi-cs42l43.c"
},
"digest": {
"line_hashes": [
"85696440487582173616552622727841444794",
"6160248363928552774586277454783071127",
"80611815404687391292209848339969580556",
"225044949120024921019853608363219948774"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@674328102baad76c7a06628efc01974ece5ae27f",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-38573-a1392629",
"target": {
"file": "drivers/spi/spi-cs42l43.c"
},
"digest": {
"line_hashes": [
"85696440487582173616552622727841444794",
"6160248363928552774586277454783071127",
"80611815404687391292209848339969580556",
"225044949120024921019853608363219948774"
],
"threshold": 0.9
},
"signature_version": "v1"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@139b5df757a0aa436f763b0038e0b73808d2f4b6",
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-38573-a90377dd",
"target": {
"file": "drivers/spi/spi-cs42l43.c"
},
"digest": {
"line_hashes": [
"85696440487582173616552622727841444794",
"6160248363928552774586277454783071127",
"80611815404687391292209848339969580556",
"225044949120024921019853608363219948774"
],
"threshold": 0.9
},
"signature_version": "v1"
}
]