CVE-2025-38485: iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush
Published Jul 28, 2025
·Updated
iio: accel: fxls8962af: Fix use after free in fxls8962affifoflush
Affected Software
15 affected componentsFixes available
Linux Kernel
Microsoft cbl2 kernel 5.15.186.1-1
Microsoft azl3 kernel 6.6.96.2-1
Linux Linux kernel>=5.14<6.1.147
Linux Linux kernel>=6.2<6.6.100
Linux Linux kernel>=6.7<6.12.40
Linux Linux kernel>=6.13<6.15.8
Linux Linux kernel=6.16-rc1
Linux Linux kernel=6.16-rc2
Linux Linux kernel=6.16-rc3
Linux Linux kernel=6.16-rc4
Linux Linux kernel=6.16-rc5
Linux Linux kernel=6.16-rc6
Debian Debian Linux=11.0
Microsoft azl3 kernel 6.6.96.2-2<6.6.104.2-1
6.6.104.2-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.104.2-1
Event History
Jul 28, 2025
CVE Published
via MITRE·11:21 AM
Data Sourced
via MITRE·11:21 AM
DescriptionSeverity
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·01:34 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:34 AM
SeverityAffected Software
Updated
via Microsoft·08:34 AM
SeverityAffected Software
Updated
via Microsoft·08:34 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-38485?
CVE-2025-38485 has a medium severity rating due to the use-after-free vulnerability in the Linux kernel.
2
How do I fix CVE-2025-38485?
To fix CVE-2025-38485, update your Linux kernel to the patched version that addresses this vulnerability.
3
Which versions of the Linux kernel are affected by CVE-2025-38485?
CVE-2025-38485 affects specific versions of the Linux kernel prior to the fix being applied.
4
What types of systems are impacted by CVE-2025-38485?
CVE-2025-38485 impacts systems running vulnerable versions of the Linux kernel.
5
What is the impact of exploiting CVE-2025-38485?
Exploiting CVE-2025-38485 could lead to memory corruption, potentially allowing an attacker to execute arbitrary code.