CVE-2025-40014 | Linux Kernel up to 6.14.1 drivers/spi/spi-amd.o amd_set_spi_freq speed_hz array index (Nessus ID 240657 / WID-SEC-2025-0861)
A vulnerability classified as problematic was found in Linux Kernel up to 6.14.1. Affected is the function amd_set_spi_freq of the file drivers/spi/spi-amd.o. The manipulation of the argument speed_hz results in improper validation of array index.
This vulnerability is cataloged as CVE-2025-40014. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.