CVE-2026-64602

ANALYSIS PENDING

iio: adc: spear: Initialize completion before requesting IRQ

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung Chung: "spear_adc_probe() in drivers/iio/adc/spear_adc.c registers its interrupt handler with devm_request_irq() before it initializes st->completion with init_completion(). If an interrupt arrives after devm_request_irq() and before init_completion(), the handler calls complete() on an uninitialized completion, causing a kernel panic. The probe path, in spear_adc_probe(): iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */ ... retval = devm_request_irq(&pdev->dev, irq, spear_adc_isr, 0, LPC32XXAD_NAME, st); /* register handler */ ... init_completion(&st->completion); /* initialize completion */ spear_adc_isr() calls complete(): complete(&st->completion); If the device raises an interrupt before init_completion() runs, complete() acquires the uninitialized wait.lock and walks the zeroed task_list in swake_up_locked(). The zeroed task_list makes list_empty() return false, so swake_up_locked() dereferences a NULL list entry, triggering a KASAN wild-memory-access." Fix the chance of a spurious IRQ causing an uninitialized pointer dereference by moving init_completion() above devm_request_irq().

Scores

EPSS 0.0016
EPSS Percentile 6.0%

Details

Status published
Products (25)
linux/Kernel 3.16.0 - 5.10.261linux
linux/Kernel 5.11.0 - 5.15.212linux
linux/Kernel 5.16.0 - 6.1.178linux
linux/Kernel 6.13.0 - 6.18.39linux
linux/Kernel 6.19.0 - 7.1.4linux
linux/Kernel 6.2.0 - 6.6.145linux
linux/Kernel 6.7.0 - 6.12.96linux
Linux/Linux < 3.16
Linux/Linux 3.16
Linux/Linux 5.10.261 - 5.10.*
... and 15 more
Published Aug 06, 2026
Tracked Since Aug 06, 2026