CVE-2025-37801

Source
https://cve.org/CVERecord?id=CVE-2025-37801
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37801.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-37801
Downstream
Related
Published
2025-05-08T06:26:01.980Z
Modified
2026-05-28T03:54:10.383291178Z
Summary
spi: spi-imx: Add check for spi_imx_setupxfer()
Details

In the Linux kernel, the following vulnerability has been resolved:

spi: spi-imx: Add check for spiimxsetupxfer()

Add check for the return value of spiimxsetupxfer(). spiimx->rx and spiimx->tx function pointer can be NULL when spiimxsetupxfer() return error, and make NULL pointer dereference.

Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 Call trace: 0x0 spiimxpiotransfer+0x50/0xd8 spiimxtransferone+0x18c/0x858 spitransferone_message+0x43c/0x790 __spipumptransfer_message+0x238/0x5d4 __spisync+0x2b0/0x454 spiwritethenread+0x11c/0x200

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37801.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
307c897db762d1e0feee9477276b08f6deca4a5b
Fixed
2fea0d6d7b5d27fbf55512d51851ba0a346ede52
Fixed
2b4479eb462ecb39001b38dfb331fc6028dedac8
Fixed
185d376875ea6fb4256b9dc97ee0b4d2b0fdd399
Fixed
055ef73bb1afc3f783a9a13b496770a781964a07
Fixed
951a04ab3a2db4029debfa48d380ef834b93207e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37801.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.136
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.89
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.26
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.14.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37801.json"