CVE-2026-64602: iio: adc: spear: Initialize completion before requesting IRQ
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026080653-CVE-2026-64602-c2e3@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung Chung: "spear_adc_probe() in drivers/iio/adc/spear_adc.c registers its interrupt handler with devm_request_irq() before it initializes st->completion with init_completion(). If an interrupt arrives after devm_request_irq() and before init_completion(), the handler calls complete() on an uninitialized completion, causing a kernel panic. The probe path, in spear_adc_probe(): iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */ ... retval = devm_request_irq(&pdev->dev, irq, spear_adc_isr, 0, LPC32XXAD_NAME, st); /* register handler */ ... init_completion(&st->completion); /* initialize completion */ spear_adc_isr() calls complete(): complete(&st->completion); If the device raises an interrupt before init_completion() runs, complete() acquires the uninitialized wait.lock and walks the zeroed task_list in swake_up_locked(). The zeroed task_list makes list_empty() return false, so swake_up_locked() dereferences a NULL list entry, triggering a KASAN wild-memory-access." Fix the chance of a spurious IRQ causing an uninitialized pointer dereference by moving init_completion() above devm_request_irq(). The Linux kernel CVE team has assigned CVE-2026-64602 to this issue. Affected and fixed versions =========================== Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 5.10.261 with commit aea8ae6c4d3ed58d9223360f758df6bd8b90c608 Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 5.15.212 with commit 67a49ab41320b3f721ce4be7447754ff040acbd5 Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.1.178 with commit a50757398794aaa25f908b96c6733e045466cba4 Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.6.145 with commit f3f90bc7b38ba3ff14f131cea0f8eb77624787a8 Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.12.96 with commit 37077d8271b1f24894fbc21bca1c4cd337525d31 Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 6.18.39 with commit bbfebae473ac2c8a194523b29ccb9b45f02f134c Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 7.1.4 with commit eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4 Issue introduced in 3.16 with commit b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed and fixed in 7.2-rc3 with commit 3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64602 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/iio/adc/spear_adc.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/aea8ae6c4d3ed58d9223360f758df6bd8b90c608 https://git.kernel.org/stable/c/67a49ab41320b3f721ce4be7447754ff040acbd5 https://git.kernel.org/stable/c/a50757398794aaa25f908b96c6733e045466cba4 https://git.kernel.org/stable/c/f3f90bc7b38ba3ff14f131cea0f8eb77624787a8 https://git.kernel.org/stable/c/37077d8271b1f24894fbc21bca1c4cd337525d31 https://git.kernel.org/stable/c/bbfebae473ac2c8a194523b29ccb9b45f02f134c https://git.kernel.org/stable/c/eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4 https://git.kernel.org/stable/c/3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0