Back

HIGH

spi: ch341: fix out-of-bounds memory access in ch341_transfer_one

Published Dec 24, 2025

Description

Discovered by Atuin - Automated Vulnerability Discovery Engine.

The 'len' variable is calculated as 'min(32, trans->len + 1)', which includes the 1-byte command header.

When copying data from 'trans->tx_buf' to 'ch341->tx_buf + 1', using 'len' as the length is incorrect because:

1. It causes an out-of-bounds read from 'trans->tx_buf' (which has size 'trans->len', i.e., 'len - 1' in this context). 2. It can cause an out-of-bounds write to 'ch341->tx_buf' if 'len' is CH341_PACKET_LENGTH (32). Writing 32 bytes to ch341->tx_buf + 1 overflows the buffer.

Fix this by copying 'len - 1' bytes.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Dec 24, 2025
Updated Aug 5, 2026
Reserved Dec 16, 2025
NVD
Status Deferred
Modified Jul 30, 2026
Red Hat
Severity Important
Public date Dec 24, 2025
ENISA EUVD
Assigner Linux
Published Dec 24, 2025
Updated Aug 5, 2026
Exploited since n/a
EUVD-2025-205102