SB2026080751 - Access of Uninitialized Pointer in Linux kernel iio adc driver
Published: August 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Access of Uninitialized Pointer (CVE-ID: CVE-2026-64602)
CWE-ID: CWE-824 - Access of Uninitialized Pointer
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an uninitialized pointer dereference in the spear_adc_probe() initialization path and interrupt handler in drivers/iio/adc/spear_adc.c when handling a device interrupt before completion initialization. A local user can trigger a spurious interrupt during device probe to cause a denial of service.
The issue can lead to a kernel panic and was observed as a KASAN wild-memory-access caused by complete() operating on an uninitialized completion object.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/37077d8271b1f24894fbc21bca1c4cd337525d31
- https://git.kernel.org/stable/c/3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0
- https://git.kernel.org/stable/c/67a49ab41320b3f721ce4be7447754ff040acbd5
- https://git.kernel.org/stable/c/a50757398794aaa25f908b96c6733e045466cba4
- https://git.kernel.org/stable/c/aea8ae6c4d3ed58d9223360f758df6bd8b90c608
- https://git.kernel.org/stable/c/bbfebae473ac2c8a194523b29ccb9b45f02f134c
- https://git.kernel.org/stable/c/eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4
- https://git.kernel.org/stable/c/f3f90bc7b38ba3ff14f131cea0f8eb77624787a8