cbcvebase.
CVE-2025-37970
published 2025-05-20

CVE-2025-37970: In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo Prevent…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.9th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix possible lockup in st_lsm6dsx_read_fifo Prevent st_lsm6dsx_read_fifo from falling in an infinite loop in case pattern_len is equal to zero and the device FIFO is not empty.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux>= 290a6ce11d938be52634b3ce1bbc6b78be4d23c1 < f06a1a1954527cc4ed086d926c81ff236b2adde9f06a1a1954527cc4ed086d926c81ff236b2adde9
linuxlinux>= 290a6ce11d938be52634b3ce1bbc6b78be4d23c1 < 84e39f628a3a3333add99076e4d6c8b42b12d3a084e39f628a3a3333add99076e4d6c8b42b12d3a0
linuxlinux>= 290a6ce11d938be52634b3ce1bbc6b78be4d23c1 < f3cf233c946531a92fe651ff2bd15ebbe60630a7f3cf233c946531a92fe651ff2bd15ebbe60630a7
linuxlinux>= 290a6ce11d938be52634b3ce1bbc6b78be4d23c1 < 6c4a5000618a8c44200d455c92e2f2a4db2647176c4a5000618a8c44200d455c92e2f2a4db264717
linuxlinux>= 290a6ce11d938be52634b3ce1bbc6b78be4d23c1 < da33c4167b9cc1266a97215114cb74679f881d0cda33c4167b9cc1266a97215114cb74679f881d0c
linuxlinux>= 290a6ce11d938be52634b3ce1bbc6b78be4d23c1 < a1cad8a3bca41dead9980615d35efc7bff1fd534a1cad8a3bca41dead9980615d35efc7bff1fd534
linuxlinux>= 290a6ce11d938be52634b3ce1bbc6b78be4d23c1 < 3bb6c02d6fe8347ce1785016d135ff539c20043c3bb6c02d6fe8347ce1785016d135ff539c20043c
linuxlinux>= 290a6ce11d938be52634b3ce1bbc6b78be4d23c1 < 159ca7f18129834b6f4c7eae67de48e96c752fc9159ca7f18129834b6f4c7eae67de48e96c752fc9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 4.11 < 5.4.2945.4.294
linuxlinux_kernel>= 5.11 < 5.15.1835.15.183
linuxlinux_kernel>= 5.16 < 6.1.1396.1.139
linuxlinux_kernel>= 5.5 < 5.10.2385.10.238
linuxlinux_kernel>= 6.13 < 6.14.76.14.7
linuxlinux_kernel>= 6.2 < 6.6.916.6.91

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_msrc4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.