Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
- >= 6.7, < 6.7.0-rc1
A vulnerability has been identified in the Linux kernel's Cadence QuadSPI driver, where an unclocked access to registers can occur during the driver unbind process. This issue arises because the controller is not properly runtime resumed before being disabled, leading to the unclocked access. The vulnerability affects the Linux kernel stable tree, specifically in versions prior to the latest commit that addresses this issue.
The vulnerability can lead to unclocked access on the Cadence QuadSPI controller, potentially causing undefined behavior or errors in register handling.
Users can apply the latest patch available in the Linux kernel stable tree to address this vulnerability. The patch can be downloaded as part of the Linux source code snapshot corresponding to the commit that fixes the issue.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.