Heap-based buffer overflow in Linux kernel - CVE-2026-64502
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to corrupt the heap and cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in ad_sigma_delta_clear_pending_event() when handling pending events with num_resetclks set to 0. A local user can trigger the pending-event drain path to corrupt the heap and cause a denial of service.
The issue can occur for registerless devices without an RDY GPIO and also for devices with an RDY GPIO set when the pending event condition is detected.