Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38531

20
FAUCET Score

CVE-2025-38531 is a vulnerability in the Linux kernel's st_sensors common driver, affecting the linux_kernel product. It stems from the use of uninitialized device structures within probe functions, leading to a kernel panic if devm_regulator_bulk_get_enable() fails and subsequently calls dev_err_probe(). This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring low privileges, and resulting in high availability impact (kernel panic). There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. While there's limited community discussion and media coverage, it has been addressed in Ubuntu security updates.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.12.40CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13, < 6.15.8CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.16CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
6.16CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
6.16CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 32nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
redhatCVE-2025-38531

kernel: iio: common: st_sensors: Fix use of uninitialize device structs

Aug 16, 2025
microsoft2025-Aug/CVE-2025-38531Moderate

iio: common: st_sensors: Fix use of uninitialize device structs

Aug 12, 2025

References

git.kernel.org / stable/c/3297a9016a45144883ec990bd4bd5b1d79cafb46
Patch
git.kernel.org / stable/c/610615c9668037e3eca11132063b93b2d945af13
Patch
git.kernel.org / stable/c/9f92e93e257b33e73622640a9205f8642ec16ddd
Patch
git.kernel.org / stable/c/f9d4b618f1b9e6d760cc7c15052b92f7faf47201