CVE-2025-71198
Linux Kernel 5.5-6.6.121, 6.7-6.12.67, 6.13-6.18.7 - Null Pointer Dereference in st_lsm6dsx_acc_channels Event Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection The st_lsm6dsx_acc_channels array of struct iio_chan_spec has a non-NULL event_spec field, indicating support for IIO events. However, event detection is not supported for all sensors, and if userspace tries to configure accelerometer wakeup events on a sensor device that does not support them (e.g. LSM6DS0), st_lsm6dsx_write_event() dereferences a NULL pointer when trying to write to the wakeup register. Define an additional struct iio_chan_spec array whose members have a NULL event_spec field, and use this array instead of st_lsm6dsx_acc_channels for sensors without event detection capability.
References (4)
Core 4
Core References
Scores
EPSS
0.0003
EPSS Percentile
7.8%
Details
Status
published
Products (13)
linux/Kernel
5.5.0 - 6.6.122linux
linux/Kernel
6.13.0 - 6.18.8linux
linux/Kernel
6.7.0 - 6.12.68linux
Linux/Linux
< 5.5
Linux/Linux
5.5
Linux/Linux
6.12.68 - 6.12.*
Linux/Linux
6.18.8 - 6.18.*
Linux/Linux
6.19
Linux/Linux
6.6.122 - 6.6.*
Linux/Linux
b5969abfa8b8ed43ebd93479d394f664bd4a5a87 - 4d60ffcdedfe2cdb68a1cde19bb292bc67451629
... and 3 more
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026