PatchSiren cyber security CVE debrief
CVE-2025-21845 Linux CVE debrief
CVE-2025-21845 is a Linux kernel availability issue in the MTD SPI-NOR SST write path. The vulnerability was introduced by a refactor in the SST write helper and can cause a warning and kernel crash when a write request is processed, because only one byte is written instead of the requested length.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-03-12
- Original CVE updated
- 2026-06-01
- Advisory published
- 2025-03-12
- Advisory updated
- 2026-06-01
Who should care
Kernel maintainers, distro security teams, and operators of Linux systems that use the MTD SPI-NOR SST flash path should prioritize this advisory, especially where local users or services can trigger MTD writes.
Technical summary
The CVE description states that commit 18bcb4aa54ea introduced a regression in sst_nor_write_data(), where the function writes only one byte regardless of the number of bytes passed in. The result is a failed write and a kernel warning/crash during MTD write operations, with the provided trace showing the failure path through mtdchar_write() and sst_nor_write_data(). NVD lists affected kernel ranges as 6.12 through 6.12.17, 6.13 through 6.13.5, and 6.14 release candidates rc1 through rc3.
Defensive priority
Medium. The issue is primarily a local denial-of-service condition, but it affects core kernel storage paths and should be patched promptly on any system that exposes the affected MTD SPI-NOR SST code path.
Recommended defensive actions
- Apply the vendor or stable kernel fixes referenced in the official Git kernel patch links.
- Backport the fix to any supported kernel branches that include the affected SST SPI-NOR code.
- Upgrade to a kernel version outside the affected ranges listed by NVD where practical.
- Validate systems that use MTD write utilities or services against the affected flash path and confirm they no longer trigger warnings or crashes.
- Monitor kernel logs for sst_nor_write_data warnings or write failures after patching to confirm remediation.
Evidence notes
This debrief is based on the CVE description and NVD metadata supplied in the source corpus. The description explicitly identifies a regression in drivers/mtd/spi-nor/sst.c causing only one byte to be written and includes a crash trace. NVD metadata supplies the affected version criteria and CVSS vector, and the official Git kernel references indicate patches are available.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-21845 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-21845
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-21845 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-21845
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/539bd20352832b9244238a055eb169ccf1c41ff6
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9553391f32f8c43e12fc7c04e1035160b5ea20bf
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/bb1accc7e0f688886f0c634f2e878b8ac4ee6a58
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f7c14993dc2f1eca661975c0ff90a6e2098ecd41
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.