CVE-2025-68352 is a Linux kernel vulnerability in the ch341 SPI driver, specifically an out-of-bounds memory access during the ch341_transfer_one function. This flaw arises from incorrect length calculations when copying data, leading to potential out-of-bounds reads from the transmit buffer and out-of-bounds writes to the internal driver buffer. While no CVSS score is provided, its FAUCET Risk Score is 7/100, indicating a low-to-moderate severity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.11CNA affecteddefault affected | |
| Linux | Linux | >= 8846739f52afa07e63395c80227dc544f54bd7b1, < 545d1287e40a55242f6ab68bcc1ba3b74088b1bc, >= 8846739f52afa07e63395c80227dc544f54bd7b1, < 81841da1f30f66a850cc8796d99ba330aad9d696, >= 8846739f52afa07e63395c80227dc544f54bd7b1, < cad6c0fd6f3c0e76a1f75df4bce3b08a13f08974, >= 8846739f52afa07e63395c80227dc544f54bd7b1, < ea1e43966cd03098fcd5f0d72e6c2901d45fa08dCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (OEM) vulnerabilities
Apr 6, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Real-time) vulnerabilities
Mar 23, 2026Linux kernel vulnerabilities
Mar 17, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: spi: ch341: fix out-of-bounds memory access in ch341_transfer_one
Dec 24, 2025