cbcvebase.
CVE-2025-71198
published 2026-02-04

CVE-2025-71198: In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection The…

PriorityP419high7.8
EPSS
0.17%
6.4th percentile
In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection The st_lsm6dsx_acc_channels array of struct iio_chan_spec has a non-NULL event_spec field, indicating support for IIO events. However, event detection is not supported for all sensors, and if userspace tries to configure accelerometer wakeup events on a sensor device that does not support them (e.g. LSM6DS0), st_lsm6dsx_write_event() dereferences a NULL pointer when trying to write to the wakeup register. Define an additional struct iio_chan_spec array whose members have a NULL event_spec field, and use this array instead of st_lsm6dsx_acc_channels for sensors without event detection capability.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.8-1 (forky)linux 6.18.8-1 (forky)
linuxlinux
linuxlinux>= b5969abfa8b8ed43ebd93479d394f664bd4a5a87 < 7673167fac9323110973a3300637adba7d45de3a7673167fac9323110973a3300637adba7d45de3a
linuxlinux>= b5969abfa8b8ed43ebd93479d394f664bd4a5a87 < 4d60ffcdedfe2cdb68a1cde19bb292bc674516294d60ffcdedfe2cdb68a1cde19bb292bc67451629
linuxlinux>= b5969abfa8b8ed43ebd93479d394f664bd4a5a87 < 81ed6e42d6e555dd978c9dd5e3f7c20cb121221b81ed6e42d6e555dd978c9dd5e3f7c20cb121221b
linuxlinux>= b5969abfa8b8ed43ebd93479d394f664bd4a5a87 < c34e2e2d67b3bb8d5a6d09b0d6dac845cdd13fb3c34e2e2d67b3bb8d5a6d09b0d6dac845cdd13fb3
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 5.5.0 < 6.6.1226.6.122
linuxlinux_kernel>= 6.13.0 < 6.18.86.18.8
linuxlinux_kernel>= 6.7.0 < 6.12.686.12.68
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fde-6.17
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.17
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.