CVE-2025-71198

Linux Kernel 5.5-6.6.121, 6.7-6.12.67, 6.13-6.18.7 - Null Pointer Dereference in st_lsm6dsx_acc_channels Event Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection The st_lsm6dsx_acc_channels array of struct iio_chan_spec has a non-NULL event_spec field, indicating support for IIO events. However, event detection is not supported for all sensors, and if userspace tries to configure accelerometer wakeup events on a sensor device that does not support them (e.g. LSM6DS0), st_lsm6dsx_write_event() dereferences a NULL pointer when trying to write to the wakeup register. Define an additional struct iio_chan_spec array whose members have a NULL event_spec field, and use this array instead of st_lsm6dsx_acc_channels for sensors without event detection capability.

Scores

EPSS 0.0003
EPSS Percentile 7.8%

Details

Status published
Products (13)
linux/Kernel 5.5.0 - 6.6.122linux
linux/Kernel 6.13.0 - 6.18.8linux
linux/Kernel 6.7.0 - 6.12.68linux
Linux/Linux < 5.5
Linux/Linux 5.5
Linux/Linux 6.12.68 - 6.12.*
Linux/Linux 6.18.8 - 6.18.*
Linux/Linux 6.19
Linux/Linux 6.6.122 - 6.6.*
Linux/Linux b5969abfa8b8ed43ebd93479d394f664bd4a5a87 - 4d60ffcdedfe2cdb68a1cde19bb292bc67451629
... and 3 more
Published Feb 04, 2026
Tracked Since Feb 18, 2026