Junglewise Threat Intelligence

CVE-2025-40356: Linux Kernel Rockchip SFC driver incorrect DMA-API usage

CVE-2025-40356 · Severity: high · CVSS 7.8 · Published 2025-12-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Rockchip Serial Flash Controller (SFC) driver, which manages data transfers between the system and flash storage. The driver incorrectly handled memory addresses during data transfers, which could lead to system instability or unauthorized access to sensitive information. This issue primarily affects devices using Rockchip processors, such as certain single-board computers.

Technical details

The vulnerability stems from improper DMA-API usage in the 'spi-rockchip-sfc.c' driver. Specifically, the driver used 'virt_to_phys()' to obtain DMA addresses for transfer buffers instead of the standard 'dma_map_single()' call. This resulted in the kernel attempting to synchronize DMA memory that had not been properly allocated or mapped, triggering DMA-API debug warnings and potential memory corruption. An attacker with local access could potentially exploit this flaw to cause a denial-of-service (kernel panic) or achieve privilege escalation. The issue has been resolved by implementing proper 'dma_map_single()' and 'dma_unmap_single()' calls in the probe and remove functions.

Affected products

  • Linux Linux Kernel 6.14, 6.17.6, 6.18

Timeline

  • 2025-10-03: patched: Initial fix authored by Marek Szyprowski
  • 2025-12-16: disclosed: CVE published by kernel.org

References

Related threats