All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-64602: iio: adc: spear: Initialize completion before requesting IRQ
Date: Thu,  6 Aug 2026 09:14:04 +0200	[thread overview]
Message-ID: <2026080653-CVE-2026-64602-c2e3@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

iio: adc: spear: Initialize completion before requesting IRQ

In the report from Jaeyoung Chung:

"spear_adc_probe() in drivers/iio/adc/spear_adc.c registers its
interrupt handler with devm_request_irq() before it initializes
st->completion with init_completion(). If an interrupt arrives after
devm_request_irq() and before init_completion(), the handler calls
complete() on an uninitialized completion, causing a kernel panic.

The probe path, in spear_adc_probe():

    iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */
    ...
    retval = devm_request_irq(&pdev->dev, irq, spear_adc_isr, 0,
                              LPC32XXAD_NAME, st);           /* register handler */
    ...
    init_completion(&st->completion);                       /* initialize completion */

spear_adc_isr() calls complete():

    complete(&st->completion);

If the device raises an interrupt before init_completion() runs,
complete() acquires the uninitialized wait.lock and walks the zeroed
task_list in swake_up_locked(). The zeroed task_list makes list_empty()
return false, so swake_up_locked() dereferences a NULL list entry,
triggering a KASAN wild-memory-access."

Fix the chance of a spurious IRQ causing an uninitialized pointer
dereference by moving init_completion() above devm_request_irq().

The Linux kernel CVE team has assigned CVE-2026-64602 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 5.10.261 with commit aea8ae6c4d3ed58d9223360f758df6bd8b90c608
	Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 5.15.212 with commit 67a49ab41320b3f721ce4be7447754ff040acbd5
	Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.1.178 with commit a50757398794aaa25f908b96c6733e045466cba4
	Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.6.145 with commit f3f90bc7b38ba3ff14f131cea0f8eb77624787a8
	Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.12.96 with commit 37077d8271b1f24894fbc21bca1c4cd337525d31
	Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.18.39 with commit bbfebae473ac2c8a194523b29ccb9b45f02f134c
	Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 7.1.4 with commit eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4
	Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 7.2-rc3 with commit 3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64602
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/iio/adc/spear_adc.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/aea8ae6c4d3ed58d9223360f758df6bd8b90c608
	https://git.kernel.org/stable/c/67a49ab41320b3f721ce4be7447754ff040acbd5
	https://git.kernel.org/stable/c/a50757398794aaa25f908b96c6733e045466cba4
	https://git.kernel.org/stable/c/f3f90bc7b38ba3ff14f131cea0f8eb77624787a8
	https://git.kernel.org/stable/c/37077d8271b1f24894fbc21bca1c4cd337525d31
	https://git.kernel.org/stable/c/bbfebae473ac2c8a194523b29ccb9b45f02f134c
	https://git.kernel.org/stable/c/eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4
	https://git.kernel.org/stable/c/3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0

                 reply	other threads:[~2026-08-06  7:14 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026080653-CVE-2026-64602-c2e3@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.