Executive brief
A timing issue in the Linux kernel's SPI-NAND flash driver causes NAND configuration register writes to be applied one operation late, potentially leaving flash devices in an unintended state. On affected devices like those using ESMT F50L1G41LB chips, this can cause the flash to become unusable and render the device unbootable when OTP (One-Time Programmable) mode is inadvertently left enabled.
Technical details
The vulnerability exists in the qcom_spi_send_cmdaddr() function within the spi-qpic-snand driver, which executes NAND commands before the associated feature values are written to the NAND_FLASH_FEATURES register. For SET_FEATURE commands, the value is placed into the register after NAND_EXEC_CMD is executed, causing the chip to be programmed with stale register contents from the previous operation. The attacker vector is local/adjacent through MTD registration routines (e.g., spinand_otp_rw() during device initialization). This results in configuration values being off-by-one in their application, so disabling OTP mode actually applies the previous enable command, leaving the chip in OTP mode and causing all subsequent array reads to return OTP data and writes to fail. The fix writes the feature value to NAND_FLASH_FEATURES within the same transaction before NAND_EXEC_CMD and copies only the required bytes to avoid buffer overruns.
Affected products
- Linux Linux Kernel 6.18 and later (timing window opened by OTP support addition)
Timeline
- 2026-08-28: disclosed