Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7173: fix channels index for syscalib_mode Fix the index used to look up the channel when accessing the syscalib_mode attribute. The address field is a 0-based index (same as scan_index) that it used to access the channel in the ad7173_channels array throughout the driver. The channels field, on the other hand, may not match the address field depending on the channel configuration specified in the device tree and could result in an out-of-bounds access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.14, < 6.16.4 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/0eb8d7b25397330beab8ee62c681975b79f37223Patch
- https://git.kernel.org/stable/c/2def1a8691eb43654da0ae0d2fdb3722e20262a5Patch
FAQ
What is CVE-2025-39786?
CVE-2025-39786 is a vulnerability with a CVSS score of 7.1 (HIGH). In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7173: fix channels index for syscalib_mode Fix the index used to look up the channel when accessing the syscalib_mode ...
How severe is CVE-2025-39786?
CVE-2025-39786 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-39786?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.