Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-40356

7.8 · HIGH
Published Dec 16, 2025 EPSS 0.14% (4th pctl)

Overview

CVE-2025-40356 is a high-severity vulnerability. It was published on December 16, 2025 and has a CVSS 3.1 base score of 7.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

spi: rockchip-sfc: Fix DMA-API usage

Use DMA-API dma_map_single() call for getting the DMA address of the

transfer buffer instead of hacking with virt_to_phys().

This fixes the following DMA-API debug warning:

------------[ cut here ]------------

DMA-API: rockchip-sfc fe300000.spi: device driver tries to sync DMA memory it has not allocated [device address=0x000000000cf70000] [size=288 bytes]

WARNING: kernel/dma/debug.c:1106 at check_sync+0x1d8/0x690, CPU#2: systemd-udevd/151

Modules linked in: ...

Hardware name: Hardkernel ODROID-M1 (DT)

pstate: 604000c9 (nZCv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)

pc : check_sync+0x1d8/0x690

lr : check_sync+0x1d8/0x690

..

Call trace:

check_sync+0x1d8/0x690 (P)

debug_dma_sync_single_for_cpu+0x84/0x8c

__dma_sync_single_for_cpu+0x88/0x234

rockchip_sfc_exec_mem_op+0x4a0/0x798 [spi_rockchip_sfc]

spi_mem_exec_op+0x408/0x498

spi_nor_read_data+0x170/0x184

spi_nor_read_sfdp+0x74/0

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2025-40356?

CVE-2025-40356 is a high-severity vulnerability. It was published on December 16, 2025 and has a CVSS 3.1 base score of 7.8 (HIGH).

How severe is CVE-2025-40356?

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2025-40356?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-40356?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-40356 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.