CVE-2025-38133
Linux Linux, linux kernel
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad4851: fix ad4858 chan pointer handling The pointer returned from ad4851_parse_channels_common() is incremented internally as each channel is populated. In ad4858_parse_channels(), the same pointer was further incremented while setting ext_scan_type fields for each channel. This resulted in indio_dev->channels being set to a pointer past the end of the allocated array, potentially causing memory corruption or undefined behavior. Fix this by iterating over the channels using an explicit index instead of incrementi...
- CVSS
- 7.8
- EPSS
- 0.16% 5.46% percentile
- CISA KEV
- Not listed
- Published
- 2025.07.03