From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-64602: iio: adc: spear: Initialize completion before requesting IRQ
Date: Thu, 6 Aug 2026 09:14:04 +0200 [thread overview]
Message-ID: <2026080653-CVE-2026-64602-c2e3@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: spear: Initialize completion before requesting IRQ
In the report from Jaeyoung Chung:
"spear_adc_probe() in drivers/iio/adc/spear_adc.c registers its
interrupt handler with devm_request_irq() before it initializes
st->completion with init_completion(). If an interrupt arrives after
devm_request_irq() and before init_completion(), the handler calls
complete() on an uninitialized completion, causing a kernel panic.
The probe path, in spear_adc_probe():
iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */
...
retval = devm_request_irq(&pdev->dev, irq, spear_adc_isr, 0,
LPC32XXAD_NAME, st); /* register handler */
...
init_completion(&st->completion); /* initialize completion */
spear_adc_isr() calls complete():
complete(&st->completion);
If the device raises an interrupt before init_completion() runs,
complete() acquires the uninitialized wait.lock and walks the zeroed
task_list in swake_up_locked(). The zeroed task_list makes list_empty()
return false, so swake_up_locked() dereferences a NULL list entry,
triggering a KASAN wild-memory-access."
Fix the chance of a spurious IRQ causing an uninitialized pointer
dereference by moving init_completion() above devm_request_irq().
The Linux kernel CVE team has assigned CVE-2026-64602 to this issue.
Affected and fixed versions
===========================
Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 5.10.261 with commit aea8ae6c4d3ed58d9223360f758df6bd8b90c608
Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 5.15.212 with commit 67a49ab41320b3f721ce4be7447754ff040acbd5
Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.1.178 with commit a50757398794aaa25f908b96c6733e045466cba4
Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.6.145 with commit f3f90bc7b38ba3ff14f131cea0f8eb77624787a8
Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.12.96 with commit 37077d8271b1f24894fbc21bca1c4cd337525d31
Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.18.39 with commit bbfebae473ac2c8a194523b29ccb9b45f02f134c
Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 7.1.4 with commit eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4
Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 7.2-rc3 with commit 3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-64602
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/iio/adc/spear_adc.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/aea8ae6c4d3ed58d9223360f758df6bd8b90c608
https://git.kernel.org/stable/c/67a49ab41320b3f721ce4be7447754ff040acbd5
https://git.kernel.org/stable/c/a50757398794aaa25f908b96c6733e045466cba4
https://git.kernel.org/stable/c/f3f90bc7b38ba3ff14f131cea0f8eb77624787a8
https://git.kernel.org/stable/c/37077d8271b1f24894fbc21bca1c4cd337525d31
https://git.kernel.org/stable/c/bbfebae473ac2c8a194523b29ccb9b45f02f134c
https://git.kernel.org/stable/c/eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4
https://git.kernel.org/stable/c/3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0
reply other threads:[~2026-08-06 7:14 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026080653-CVE-2026-64602-c2e3@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.