PT-2026-64723 · Linux · Linux
CVE-2026-64502
·
Publicado
2026-07-25
·
Atualizado
2026-07-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ad sigma delta: fix clear pending event for registerless devices
ad sigma delta clear pending event() falls through to the status register
read path for devices with has registers = false and no rdy gpiod. For
such devices, ad sd read reg() skips the address byte entirely and clocks
raw MISO bytes with no address phase — making it byte-for-byte identical
to reading conversion data. If a pending conversion result is present,
this partially consumes it and corrupts the data stream for the subsequent
ad sd read reg() call in ad sigma delta single conversion().
Furthermore, with num resetclks = 0 on these devices, data read len
evaluates to 0. If the clocked byte has bit 7 clear, pending event is set
and the code attempts memset(data + 2, 0xff, 0 - 1), overflowing to
SIZE MAX and corrupting the heap.
Fix by returning 0 immediately when neither rdy gpiod nor has registers
is set. This is safe for all current registerless devices: ad7191 and
ad7780 (with powerdown GPIO) are reset between conversions by CS
deassertion, so there is no stale result to drain; ad7780 (without
powerdown GPIO) and max11205 are continuously-converting and cycle ~DRDY
at the output data rate regardless of whether the previous result was
read, so the next falling edge fires naturally.
A future registerless device that holds ~DRDY asserted until data is read
would be broken by this early return and would require either
num resetclks set or a rdy-gpio.
The same heap corruption is reachable on any device with rdy gpiod set
but num resetclks = 0: if the GPIO indicates a pending event, the drain
path executes memset(data + 2, 0xff, 0 - 1) regardless of has registers.
Add an explicit data read len == 0 guard after the pending event check;
the stale result is then consumed by the first ad sd read reg() call in
ad sigma delta single conversion().
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux