cbcvebase.
CVE-2025-68330
published 2025-12-22

CVE-2025-68330: In the Linux kernel, the following vulnerability has been resolved: iio: accel: bmc150: Fix irq assumption regression The code in bmc150-accel-core.c…

PriorityP422high7.8
EPSS
0.17%
6.3th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: accel: bmc150: Fix irq assumption regression The code in bmc150-accel-core.c unconditionally calls bmc150_accel_set_interrupt() in the iio_buffer_setup_ops, such as on the runtime PM resume path giving a kernel splat like this if the device has no interrupts: Unable to handle kernel NULL pointer dereference at virtual address 00000001 when read PC is at bmc150_accel_set_interrupt+0x98/0x194 LR is at __pm_runtime_resume+0x5c/0x64 (...) Call trace: bmc150_accel_set_interrupt from bmc150_accel_buffer_postenable+0x40/0x108 bmc150_accel_buffer_postenable from __iio_update_buffers+0xbe0/0xcbc __iio_update_buffers from enable_store+0x84/0xc8 enable_store from kernfs_fop_write_iter+0x154/0x1b4 This bug seems to have been in the driver since the beginning, but it only manifests recently, I do not know why. Store the IRQ number in the state struct, as this is a common pattern in other drivers, then use this to determine if we have IRQ support or not.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= c16bff4844ffa678ba0c9d077e9797506924ccdd < aad9d048a3211c48ec02efa405bf462856feb862aad9d048a3211c48ec02efa405bf462856feb862
linuxlinux>= c16bff4844ffa678ba0c9d077e9797506924ccdd < c891f504bb66604c822e7985e093cf39b97fdeb0c891f504bb66604c822e7985e093cf39b97fdeb0
linuxlinux>= c16bff4844ffa678ba0c9d077e9797506924ccdd < cdd4a9e98004bd7c7488311951fa6dbae38b2b80cdd4a9e98004bd7c7488311951fa6dbae38b2b80
linuxlinux>= c16bff4844ffa678ba0c9d077e9797506924ccdd < 65ad4ed983fd9ee0259d86391d6a53f78203918c65ad4ed983fd9ee0259d86391d6a53f78203918c
linuxlinux>= c16bff4844ffa678ba0c9d077e9797506924ccdd < 93eaa5ddc5fc4f50ac396afad8ce261102ebd4f393eaa5ddc5fc4f50ac396afad8ce261102ebd4f3
linuxlinux>= c16bff4844ffa678ba0c9d077e9797506924ccdd < 3aa385a9c75c09b59dcab2ff76423439d23673ab3aa385a9c75c09b59dcab2ff76423439d23673ab
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 4.2.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 6.13.0 < 6.17.116.17.11
linuxlinux_kernel>= 6.2.0 < 6.6.1196.6.119
linuxlinux_kernel>= 6.7.0 < 6.12.616.12.61
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
ubuntulinux-azure-5.15
ubuntulinux-xilinx

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.