cbcvebase.
CVE-2025-37969
published 2025-05-20

CVE-2025-37969: In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo Prevent…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.9th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_tagged_fifo Prevent st_lsm6dsx_read_tagged_fifo from falling in an infinite loop in case pattern_len is equal to zero and the device FIFO is not empty.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux>= 801a6e0af0c6cedca2e99155e343ad385a50f08e < 4db7d923a8c298788181b796f71adf6ca499f9664db7d923a8c298788181b796f71adf6ca499f966
linuxlinux>= 801a6e0af0c6cedca2e99155e343ad385a50f08e < 76727a1d81afde77d21ea8feaeb12d34605be6f476727a1d81afde77d21ea8feaeb12d34605be6f4
linuxlinux>= 801a6e0af0c6cedca2e99155e343ad385a50f08e < 35b8c0a284983b71d92d082c54b7eb655ed4194f35b8c0a284983b71d92d082c54b7eb655ed4194f
linuxlinux>= 801a6e0af0c6cedca2e99155e343ad385a50f08e < 16857370b3a30663515956b3bd27f3def6a2cf0616857370b3a30663515956b3bd27f3def6a2cf06
linuxlinux>= 801a6e0af0c6cedca2e99155e343ad385a50f08e < 9ce662851380fe2018e36e15c0bdcb1ad177ed959ce662851380fe2018e36e15c0bdcb1ad177ed95
linuxlinux>= 801a6e0af0c6cedca2e99155e343ad385a50f08e < dadf9116108315f2eb14c7415c7805f392c476b4dadf9116108315f2eb14c7415c7805f392c476b4
linuxlinux>= 801a6e0af0c6cedca2e99155e343ad385a50f08e < 9ddb4cf2192c213e4dba1733bbcdc94cf6d85bf79ddb4cf2192c213e4dba1733bbcdc94cf6d85bf7
linuxlinux>= 801a6e0af0c6cedca2e99155e343ad385a50f08e < 8114ef86e2058e2554111b793596f17bee23fa158114ef86e2058e2554111b793596f17bee23fa15
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 4.20 < 5.4.2945.4.294
linuxlinux_kernel>= 5.11 < 5.15.1835.15.183
linuxlinux_kernel>= 5.16 < 6.1.1396.1.139
linuxlinux_kernel>= 5.5 < 5.10.2385.10.238
linuxlinux_kernel>= 6.13 < 6.14.76.14.7
linuxlinux_kernel>= 6.2 < 6.6.916.6.91

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_msrc7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.