Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +3 more
A vulnerability in the Linux kernel's Microchip QSPI driver has been addressed. The issue arose because the driver improperly handled the maximum frequency parameter during its operation support checks, leading to a failure when probing attached memory devices. This vulnerability was introduced when the driver was modified to support per-operation frequency adjustments, but the maximum frequency value was not valid at the time of the probe, causing a division by zero error. As a result, the driver failed to correctly initialize the memory device.
The vulnerability caused the probing of attached memory devices to fail, disrupting normal device initialization and potentially leading to broader system functionality issues.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.