CVE-2026-64500
Last modified
CVE-2026-64500 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: iio: adc: lpc32xx: Initialize completion before requesting IRQ In the report from Jaeyoung Chung: "lpc32xx_adc_probe() in drivers/iio/adc/lpc32xx_adc.c registers its interrupt handler with devm_request_irq() before it initializes st->completion with init_completion(). If an interrupt arrives after devm_request_irq() and before init_completion(), the handler calls complete() on an uninitialized completion, causing a kernel panic. The probe path, in lpc32xx_adc_probe(): iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */ ... retval = devm_request_irq(&pdev->dev, irq, lpc32xx_adc_isr, 0, LPC32XXAD_NAME, st); /* register handler */ ... init_completion(&st->completion); /* initialize completion */ lpc32xx_adc_isr() calls complete(): complete(&st->completion); If the device raises an interrupt before init_completion() runs, complete() acquires the uninitialized wait.lock and walks the zeroed task_list in swake_up_locked().
Description
In the Linux kernel, the following vulnerability has been resolved: iio: adc: lpc32xx: Initialize completion before requesting IRQ In the report from Jaeyoung Chung: "lpc32xx_adc_probe() in drivers/iio/adc/lpc32xx_adc.c registers its interrupt handler with devm_request_irq() before it initializes st->completion with init_completion(). If an interrupt arrives after devm_request_irq() and before init_completion(), the handler calls complete() on an uninitialized completion, causing a kernel panic. The probe path, in lpc32xx_adc_probe(): iodev = devm_iio_device_alloc(&pdev->dev, sizeof(*st)); /* st kzalloc-zeroed */ ... retval = devm_request_irq(&pdev->dev, irq, lpc32xx_adc_isr, 0, LPC32XXAD_NAME, st); /* register handler */ ... init_completion(&st->completion); /* initialize completion */ lpc32xx_adc_isr() calls complete(): complete(&st->completion); If the device raises an interrupt before init_completion() runs, complete() acquires the uninitialized wait.lock and walks the zeroed task_list in swake_up_locked(). The zeroed task_list makes list_empty() return false, so swake_up_locked() dereferences a NULL list entry, triggering a KASAN wild-memory-access." Fix the chance of a spurious IRQ causing an uninitialized pointer dereference by moving init_completion() above devm_request_irq().
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 7901b2a1453e48c9defff2c97c67d3089bf4df7a, < 7090c0d29708ee305022d0ea7b37612b33242fa2; >= 7901b2a1453e48c9defff2c97c67d3089bf4df7a, < 0e33587967b356519aa6f220b5b43c6976320397; >= 7901b2a1453e48c9defff2c97c67d3089bf4df7a, < 1ddf7b6ffb8ebb22b92a184a9eaa76277ef0c7cd; >= 7901b2a1453e48c9defff2c97c67d3089bf4df7a, < 820c4f15353efe9a9429ae86ccceeaf4e0e4e585; >= 7901b2a1453e48c9defff2c97c67d3089bf4df7a, < 48eccc6caed4e62c0f199ab3a3772fa969cd3b2d; >= 7901b2a1453e48c9defff2c97c67d3089bf4df7a, < 9e2e8b8cdfd37ae7c7a8a5c96c59e98a768731c4; >= 7901b2a1453e48c9defff2c97c67d3089bf4df7a, < 2f18c5551aa97ca7f39dbb151c67c9053ccadc17; >= 7901b2a1453e48c9defff2c97c67d3089bf4df7a, < e561b35633f450ee607e87a6401d97f156a0cd54 |
| Linux | Linux | 4.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-64500?
How severe is CVE-2026-64500?
How do I fix CVE-2026-64500?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64495In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64496In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-64497In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64498In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64499In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6450A CRL critical extension bypass exists in ParseCRL_Extension…5.3
- CVE-2026-64501In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-64502In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64503In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64504In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64505In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64506In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-64500?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
