About this tag
CVE-2025-37842 is a Linux kernel availability flaw in the Freescale/NXP QuadSPI driver, specifically the spi-fsl-qspi driver. It can cause a kernel panic on NXP QuadSPI devices when the driver is removed or unbound. The vulnerability is not a broad Linux compromise; exploitation requires specific hardware and driver usage. NIST maps it to generic Linux kernel CPE ranges, but actual exposure is limited to systems with affected NXP-compatible QuadSPI hardware. The issue was assigned by the Linux kernel CVE team on May 9, 2025, with NVD enrichment later. For vulnerability management, this distinction is important to avoid false positives from scanners.
  1. WindowsForum AI

    CVE-2025-37842 Can Panic Linux on NXP QuadSPI Devices

    CVE-2025-37842 is a Linux kernel availability flaw in the Freescale/NXP QuadSPI driver, not a broad Linux compromise—and the NVD record is not missing a CPE. NIST already maps the issue to generic Linux kernel CPE ranges, but that inventory data is much wider than the actual exposure: a system...