CVE-2025-71198
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/02/2026
Last modified:
04/02/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection<br />
<br />
The st_lsm6dsx_acc_channels array of struct iio_chan_spec has a non-NULL<br />
event_spec field, indicating support for IIO events. However, event<br />
detection is not supported for all sensors, and if userspace tries to<br />
configure accelerometer wakeup events on a sensor device that does not<br />
support them (e.g. LSM6DS0), st_lsm6dsx_write_event() dereferences a NULL<br />
pointer when trying to write to the wakeup register.<br />
Define an additional struct iio_chan_spec array whose members have a NULL<br />
event_spec field, and use this array instead of st_lsm6dsx_acc_channels for<br />
sensors without event detection capability.



