« Volver al listado

CVE-2025-68330

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

iio: accel: bmc150: Fix irq assumption regression

The code in bmc150-accel-core.c unconditionally calls bmc150_accel_set_interrupt() in the iio_buffer_setup_ops, such as on the runtime PM resume path giving a kernel splat like this if the device has no interrupts:

This bug seems to have been in the driver since the beginning, but it only manifests recently, I do not know why.

Store the IRQ number in the state struct, as this is a common pattern in other drivers, then use this to determine if we have IRQ support or not.

Detalles técnicos trazas, registros y código del informe original
Unable to handle kernel NULL pointer dereference at virtual
  address 00000001 when read

PC is at bmc150_accel_set_interrupt+0x98/0x194
LR is at __pm_runtime_resume+0x5c/0x64
(...)
Call trace:
bmc150_accel_set_interrupt from bmc150_accel_buffer_postenable+0x40/0x108
bmc150_accel_buffer_postenable from __iio_update_buffers+0xbe0/0xcbc
__iio_update_buffers from enable_store+0x84/0xc8
enable_store from kernfs_fop_write_iter+0x154/0x1b4

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-68330",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c16bff4844ffa678ba0c9d077e9797506924ccdd",
              "lessThan": "aad9d048a3211c48ec02efa405bf462856feb862",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c16bff4844ffa678ba0c9d077e9797506924ccdd",
              "lessThan": "c891f504bb66604c822e7985e093cf39b97fdeb0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c16bff4844ffa678ba0c9d077e9797506924ccdd",
              "lessThan": "cdd4a9e98004bd7c7488311951fa6dbae38b2b80",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c16bff4844ffa678ba0c9d077e9797506924ccdd",
              "lessThan": "65ad4ed983fd9ee0259d86391d6a53f78203918c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c16bff4844ffa678ba0c9d077e9797506924ccdd",
              "lessThan": "93eaa5ddc5fc4f50ac396afad8ce261102ebd4f3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c16bff4844ffa678ba0c9d077e9797506924ccdd",
              "lessThan": "3aa385a9c75c09b59dcab2ff76423439d23673ab",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/iio/accel/bmc150-accel-core.c",
            "drivers/iio/accel/bmc150-accel.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.197",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.159",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.119",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.61",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.17.11",
              "versionType": "semver",
              "lessThanOrEqual": "6.17.*"
            },
            {
              "status": "unaffected",
              "version": "6.18",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/iio/accel/bmc150-accel-core.c",
            "drivers/iio/accel/bmc150-accel.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-22T17:16:00.680",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3aa385a9c75c09b59dcab2ff76423439d23673ab",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/65ad4ed983fd9ee0259d86391d6a53f78203918c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/93eaa5ddc5fc4f50ac396afad8ce261102ebd4f3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aad9d048a3211c48ec02efa405bf462856feb862",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c891f504bb66604c822e7985e093cf39b97fdeb0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cdd4a9e98004bd7c7488311951fa6dbae38b2b80",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: accel: bmc150: Fix irq assumption regression\n\nThe code in bmc150-accel-core.c unconditionally calls\nbmc150_accel_set_interrupt() in the iio_buffer_setup_ops,\nsuch as on the runtime PM resume path giving a kernel\nsplat like this if the device has no interrupts:\n\nUnable to handle kernel NULL pointer dereference at virtual\n  address 00000001 when read\n\nPC is at bmc150_accel_set_interrupt+0x98/0x194\nLR is at __pm_runtime_resume+0x5c/0x64\n(...)\nCall trace:\nbmc150_accel_set_interrupt from bmc150_accel_buffer_postenable+0x40/0x108\nbmc150_accel_buffer_postenable from __iio_update_buffers+0xbe0/0xcbc\n__iio_update_buffers from enable_store+0x84/0xc8\nenable_store from kernfs_fop_write_iter+0x154/0x1b4\n\nThis bug seems to have been in the driver since the beginning,\nbut it only manifests recently, I do not know why.\n\nStore the IRQ number in the state struct, as this is a common\npattern in other drivers, then use this to determine if we have\nIRQ support or not."
    }
  ],
  "lastModified": "2026-06-17T09:58:56.763",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}