« Volver al listado

CVE-2026-64500

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

iio: adc: lpc32xx: Initialize completion before requesting IRQ

In the report from Jaeyoung Chung:

"lpc32xx_adc_probe() in drivers/iio/adc/lpc32xx_adc.c registers its interrupt handler with devm_request_irq() before it initializes st->completion with init_completion(). If an interrupt arrives after devm_request_irq() and before init_completion(), the handler calls complete() on an uninitialized completion, causing a kernel panic.

The probe path, in lpc32xx_adc_probe():

lpc32xx_adc_isr() calls complete():

If the device raises an interrupt before init_completion() runs, complete() acquires the uninitialized wait.lock and walks the zeroed task_list in swake_up_locked().

Leer descripción completaMostrar menos

The zeroed task_list makes list_empty() return false, so swake_up_locked() dereferences a NULL list entry, triggering a KASAN wild-memory-access."

Fix the chance of a spurious IRQ causing an uninitialized pointer dereference by moving init_completion() above devm_request_irq().

Detalles técnicos trazas, registros y código del informe original
    iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */
    ...
    retval = devm_request_irq(&pdev->dev, irq, lpc32xx_adc_isr, 0,
                              LPC32XXAD_NAME, st);           /* register handler */
    ...
    init_completion(&st->completion);                       /* initialize completion */

    complete(&st->completion);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64500",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
              "lessThan": "7090c0d29708ee305022d0ea7b37612b33242fa2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
              "lessThan": "0e33587967b356519aa6f220b5b43c6976320397",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
              "lessThan": "1ddf7b6ffb8ebb22b92a184a9eaa76277ef0c7cd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
              "lessThan": "820c4f15353efe9a9429ae86ccceeaf4e0e4e585",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
              "lessThan": "48eccc6caed4e62c0f199ab3a3772fa969cd3b2d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
              "lessThan": "9e2e8b8cdfd37ae7c7a8a5c96c59e98a768731c4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
              "lessThan": "2f18c5551aa97ca7f39dbb151c67c9053ccadc17",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7901b2a1453e48c9defff2c97c67d3089bf4df7a",
              "lessThan": "e561b35633f450ee607e87a6401d97f156a0cd54",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/iio/adc/lpc32xx_adc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.96",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.39",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/iio/adc/lpc32xx_adc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-25T10:17:35.957",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0e33587967b356519aa6f220b5b43c6976320397",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1ddf7b6ffb8ebb22b92a184a9eaa76277ef0c7cd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2f18c5551aa97ca7f39dbb151c67c9053ccadc17",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/48eccc6caed4e62c0f199ab3a3772fa969cd3b2d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7090c0d29708ee305022d0ea7b37612b33242fa2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/820c4f15353efe9a9429ae86ccceeaf4e0e4e585",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9e2e8b8cdfd37ae7c7a8a5c96c59e98a768731c4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e561b35633f450ee607e87a6401d97f156a0cd54",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: lpc32xx: Initialize completion before requesting IRQ\n\nIn the report from Jaeyoung Chung:\n\n\"lpc32xx_adc_probe() in drivers/iio/adc/lpc32xx_adc.c registers its\ninterrupt handler with devm_request_irq() before it initializes\nst->completion with init_completion(). If an interrupt arrives after\ndevm_request_irq() and before init_completion(), the handler calls\ncomplete() on an uninitialized completion, causing a kernel panic.\n\nThe probe path, in lpc32xx_adc_probe():\n\n    iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */\n    ...\n    retval = devm_request_irq(&pdev->dev, irq, lpc32xx_adc_isr, 0,\n                              LPC32XXAD_NAME, st);           /* register handler */\n    ...\n    init_completion(&st->completion);                       /* initialize completion */\n\nlpc32xx_adc_isr() calls complete():\n\n    complete(&st->completion);\n\nIf the device raises an interrupt before init_completion() runs,\ncomplete() acquires the uninitialized wait.lock and walks the zeroed\ntask_list in swake_up_locked(). The zeroed task_list makes list_empty()\nreturn false, so swake_up_locked() dereferences a NULL list entry,\ntriggering a KASAN wild-memory-access.\"\n\nFix the chance of a spurious IRQ causing an uninitialized pointer\ndereference by moving init_completion() above devm_request_irq()."
    }
  ],
  "lastModified": "2026-08-17T05:17:56.020",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}