Junglewise Threat Intelligence

CVE-2025-68352: Linux Kernel out-of-bounds access in CH341 SPI driver

CVE-2025-68352 · Severity: high · CVSS 7.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was found in the Linux kernel's driver for CH341 USB-to-SPI adapters, which are hardware components used to connect computers to various peripheral devices. An attacker with local access to the system could exploit this flaw to cause a system crash or potentially gain unauthorized access to sensitive information. This issue stems from a memory handling error when the system transfers data to the USB device.

Technical details

An out-of-bounds memory access vulnerability exists in the Linux kernel SPI driver for CH341 devices (drivers/spi/spi-ch341.c). The root cause is an off-by-one error in the ch341_transfer_one function where the 'len' variable, which includes a 1-byte command header, is used as the length for a memcpy operation from the transmission buffer. This results in an out-of-bounds read from the source buffer and a potential out-of-bounds write (buffer overflow) to the destination buffer when 'len' reaches the maximum packet size of 32 bytes. A local attacker with permissions to initiate SPI transfers could exploit this to leak kernel memory or corrupt kernel structures. Patches have been released for various stable kernel branches including 6.12.y, 6.17.y, and 6.18.y.

Affected products

  • Linux Linux Kernel 6.11 to 6.12.63, 6.17.13, 6.18.2

Timeline

  • 2025-11-28: patched: Initial fix committed to mainline kernel
  • 2025-12-24: disclosed: CVE-2025-68352 published

References

Related threats