CVE-2025-21793
In the Linux kernel, the following vulnerability has been resolved: spi: sn-f-ospi: Fix division by zero When there is no dummy cycle in the spi-nor commands, both dummy bus cycle bytes and width are zero.
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: spi: sn-f-ospi: Fix division by zero When there is no dummy cycle in the spi-nor commands, both dummy bus cycle bytes and width are zero. Because of the cpu's warning when divided by zero, the warning should be avoided. Return just zero to avoid such calculations.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-369
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/3588b1c0fde2f58d166e3f94a5a58d64b893526cPatch
- https://git.kernel.org/stable/c/4df6f005bef04a3dd16c028124a1b5684db3922bPatch
- https://git.kernel.org/stable/c/7434135553bc03809a55803ee6a8dcaae6240d55Patch
- https://git.kernel.org/stable/c/966328191b4c389c0f2159fa242915f51cbc1679Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.