CVE-2025-38485 – “Linux Kernel IIO Accel FXLS8962AF Use After Free Null Pointer Dereference Vulnerability”

The following table lists the changes that have been made to the
CVE-2025-38485 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 28, 2025

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved:

    iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush

    fxls8962af_fifo_flush() uses indio_dev->active_scan_mask (with
    iio_for_each_active_channel()) without making sure the indio_dev
    stays in buffer mode.
    There is a race if indio_dev exits buffer mode in the middle of the
    interrupt that flushes the fifo. Fix this by calling
    synchronize_irq() to ensure that no interrupt is currently running when
    disabling buffer mode.

    Unable to handle kernel NULL pointer dereference at virtual address 00000000 when read
    […]
    _find_first_bit_le from fxls8962af_fifo_flush+0x17c/0x290
    fxls8962af_fifo_flush from fxls8962af_interrupt+0x80/0x178
    fxls8962af_interrupt from irq_thread_fn+0x1c/0x7c
    irq_thread_fn from irq_thread+0x110/0x1f4
    irq_thread from kthread+0xe0/0xfc
    kthread from ret_from_fork+0x14/0x2c

    Added Reference https://git.kernel.org/stable/c/1803d372460aaa9ae0188a30c9421d3f157f2f04
    Added Reference https://git.kernel.org/stable/c/1fe16dc1a2f5057772e5391ec042ed7442966c9a
    Added Reference https://git.kernel.org/stable/c/6ecd61c201b27ad2760b3975437ad2b97d725b98
    Added Reference https://git.kernel.org/stable/c/bfcda3e1015791b3a63fb4d3aad408da9cf76e8f
    Added Reference https://git.kernel.org/stable/c/dda42f23a8f5439eaac9521ce0531547d880cc54
Share the Post:

Related Posts