PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-21845 Linux CVE debrief

CVE-2025-21845 is a Linux kernel availability issue in the MTD SPI-NOR SST write path. The vulnerability was introduced by a refactor in the SST write helper and can cause a warning and kernel crash when a write request is processed, because only one byte is written instead of the requested length.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-03-12
Original CVE updated
2026-06-01
Advisory published
2025-03-12
Advisory updated
2026-06-01

Who should care

Kernel maintainers, distro security teams, and operators of Linux systems that use the MTD SPI-NOR SST flash path should prioritize this advisory, especially where local users or services can trigger MTD writes.

Technical summary

The CVE description states that commit 18bcb4aa54ea introduced a regression in sst_nor_write_data(), where the function writes only one byte regardless of the number of bytes passed in. The result is a failed write and a kernel warning/crash during MTD write operations, with the provided trace showing the failure path through mtdchar_write() and sst_nor_write_data(). NVD lists affected kernel ranges as 6.12 through 6.12.17, 6.13 through 6.13.5, and 6.14 release candidates rc1 through rc3.

Defensive priority

Medium. The issue is primarily a local denial-of-service condition, but it affects core kernel storage paths and should be patched promptly on any system that exposes the affected MTD SPI-NOR SST code path.

Recommended defensive actions

  • Apply the vendor or stable kernel fixes referenced in the official Git kernel patch links.
  • Backport the fix to any supported kernel branches that include the affected SST SPI-NOR code.
  • Upgrade to a kernel version outside the affected ranges listed by NVD where practical.
  • Validate systems that use MTD write utilities or services against the affected flash path and confirm they no longer trigger warnings or crashes.
  • Monitor kernel logs for sst_nor_write_data warnings or write failures after patching to confirm remediation.

Evidence notes

This debrief is based on the CVE description and NVD metadata supplied in the source corpus. The description explicitly identifies a regression in drivers/mtd/spi-nor/sst.c causing only one byte to be written and includes a crash trace. NVD metadata supplies the affected version criteria and CVSS vector, and the official Git kernel references indicate patches are available.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-21845 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-21845

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-21845 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21845

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/539bd20352832b9244238a055eb169ccf1c41ff6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9553391f32f8c43e12fc7c04e1035160b5ea20bf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bb1accc7e0f688886f0c634f2e878b8ac4ee6a58

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f7c14993dc2f1eca661975c0ff90a6e2098ecd41

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.