CVE-2025-38648

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-38648
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38648.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-38648
Downstream
Related
Published
2025-08-22T16:15:39Z
Modified
2025-09-06T13:01:49Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

spi: stm32: Check for cfg availability in stm32spiprobe

The stm32spiprobe function now includes a check to ensure that the pointer returned by ofdevicegetmatchdata is not NULL before accessing its members. This resolves a warning where a potential NULL pointer dereference could occur when accessing cfg->hasdevicemode.

Before accessing the 'hasdevicemode' member, we verify that 'cfg' is not NULL. If 'cfg' is NULL, an error message is logged.

This change ensures that the driver does not attempt to access configuration data if it is not available, thus preventing a potential system crash due to a NULL pointer dereference.

References

Affected packages