Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66623.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-66623
Upstream
Published
2025-08-22T16:15:39Z
Modified
2026-04-01T05:21:46.539045Z
Summary
CVE-2025-38648 affecting package kernel for versions less than 6.6.104.2-1
Details

In the Linux kernel, the following vulnerability has been resolved:

spi: stm32: Check for cfg availability in stm32spiprobe

The stm32spiprobe function now includes a check to ensure that the pointer returned by ofdevicegetmatchdata is not NULL before accessing its members. This resolves a warning where a potential NULL pointer dereference could occur when accessing cfg->hasdevicemode.

Before accessing the 'hasdevicemode' member, we verify that 'cfg' is not NULL. If 'cfg' is NULL, an error message is logged.

This change ensures that the driver does not attempt to access configuration data if it is not available, thus preventing a potential system crash due to a NULL pointer dereference.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.104.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66623.json"