-

CVE-2026-64602

iio: adc: spear: Initialize completion before requesting IRQ

In the Linux kernel, the following vulnerability has been resolved:

iio: adc: spear: Initialize completion before requesting IRQ

In the report from Jaeyoung Chung:

"spear_adc_probe() in drivers/iio/adc/spear_adc.c registers its
interrupt handler with devm_request_irq() before it initializes
st->completion with init_completion(). If an interrupt arrives after
devm_request_irq() and before init_completion(), the handler calls
complete() on an uninitialized completion, causing a kernel panic.

The probe path, in spear_adc_probe():

    iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */
    ...
    retval = devm_request_irq(&pdev->dev, irq, spear_adc_isr, 0,
                              LPC32XXAD_NAME, st);           /* register handler */
    ...
    init_completion(&st->completion);                       /* initialize completion */

spear_adc_isr() calls complete():

    complete(&st->completion);

If the device raises an interrupt before init_completion() runs,
complete() acquires the uninitialized wait.lock and walks the zeroed
task_list in swake_up_locked(). The zeroed task_list makes list_empty()
return false, so swake_up_locked() dereferences a NULL list entry,
triggering a KASAN wild-memory-access."

Fix the chance of a spurious IRQ causing an uninitialized pointer
dereference by moving init_completion() above devm_request_irq().
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed
Version < aea8ae6c4d3ed58d9223360f758df6bd8b90c608
Status affected
Version b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed
Version < 67a49ab41320b3f721ce4be7447754ff040acbd5
Status affected
Version b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed
Version < a50757398794aaa25f908b96c6733e045466cba4
Status affected
Version b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed
Version < f3f90bc7b38ba3ff14f131cea0f8eb77624787a8
Status affected
Version b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed
Version < 37077d8271b1f24894fbc21bca1c4cd337525d31
Status affected
Version b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed
Version < bbfebae473ac2c8a194523b29ccb9b45f02f134c
Status affected
Version b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed
Version < eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4
Status affected
Version b586e5d9eee038b8ee6f846cdb6cf2fcbcb2f4ed
Version < 3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.16
Status affected
Version 0
Version < 3.16
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.06
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/aea8ae6c4d3ed58d9223360f758df6bd8b90c608
https://git.kernel.org/stable/c/67a49ab41320b3f721ce4be7447754ff040acbd5
https://git.kernel.org/stable/c/a50757398794aaa25f908b96c6733e045466cba4
https://git.kernel.org/stable/c/f3f90bc7b38ba3ff14f131cea0f8eb77624787a8
https://git.kernel.org/stable/c/37077d8271b1f24894fbc21bca1c4cd337525d31
https://git.kernel.org/stable/c/bbfebae473ac2c8a194523b29ccb9b45f02f134c
https://git.kernel.org/stable/c/eb5b07c9d0ec1a9d4b6871b14793c19967d79dc4
https://git.kernel.org/stable/c/3ee2128b6f0eb0be7b6cb8f6e0f1f113a65201a0