CVE-2026-64502: iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:51:59 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072553-CVE-2026-64502-e91c@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices

ad_sigma_delta_clear_pending_event() falls through to the status register
read path for devices with has_registers = false and no rdy_gpiod. For
such devices, ad_sd_read_reg() skips the address byte entirely and clocks
raw MISO bytes with no address phase — making it byte-for-byte identical
to reading conversion data. If a pending conversion result is present,
this partially consumes it and corrupts the data stream for the subsequent
ad_sd_read_reg() call in ad_sigma_delta_single_conversion().

Furthermore, with num_resetclks = 0 on these devices, data_read_len
evaluates to 0. If the clocked byte has bit 7 clear, pending_event is set
and the code attempts memset(data + 2, 0xff, 0 - 1), overflowing to
SIZE_MAX and corrupting the heap.

Fix by returning 0 immediately when neither rdy_gpiod nor has_registers
is set. This is safe for all current registerless devices: ad7191 and
ad7780 (with powerdown GPIO) are reset between conversions by CS
deassertion, so there is no stale result to drain; ad7780 (without
powerdown GPIO) and max11205 are continuously-converting and cycle ~DRDY
at the output data rate regardless of whether the previous result was
read, so the next falling edge fires naturally.

A future registerless device that holds ~DRDY asserted until data is read
would be broken by this early return and would require either
num_resetclks set or a rdy-gpio.

The same heap corruption is reachable on any device with rdy_gpiod set
but num_resetclks = 0: if the GPIO indicates a pending event, the drain
path executes memset(data + 2, 0xff, 0 - 1) regardless of has_registers.
Add an explicit data_read_len == 0 guard after the pending event check;
the stale result is then consumed by the first ad_sd_read_reg() call in
ad_sigma_delta_single_conversion().

The Linux kernel CVE team has assigned CVE-2026-64502 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.14 with commit 132d44dc6966c1cf841ffe0f6f048165687e870b and fixed in 6.18.39 with commit 3394e0b3328422431cadaf314fa58d3717ed4936
	Issue introduced in 6.14 with commit 132d44dc6966c1cf841ffe0f6f048165687e870b and fixed in 7.1.4 with commit 3bceb26dfaf7ba805b459e41c1d0ba916862dade
	Issue introduced in 6.14 with commit 132d44dc6966c1cf841ffe0f6f048165687e870b and fixed in 7.2-rc1 with commit 91bc6767a4f55dc470d8a56b55b9f2ea09094efe

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64502
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/iio/adc/ad_sigma_delta.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/3394e0b3328422431cadaf314fa58d3717ed4936
	https://git.kernel.org/stable/c/3bceb26dfaf7ba805b459e41c1d0ba916862dade
	https://git.kernel.org/stable/c/91bc6767a4f55dc470d8a56b55b9f2ea09094efe