Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted and state leaks In… (CVE-2026-64501)

0
Medium
Published: 07/25/2026 (07/25/2026, 12:31:38 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's iio adc ad_sigma_delta driver caused the chip select (CS) line to remain asserted and allowed state leaks during SPI transfers. This occurred because certain cleanup calls were made while the CS line was still held asserted, leading to improper SPI bus state and potential concurrent access issues. The issue was fixed by adjusting the order of operations to clear the CS assertion before cleanup calls and properly managing SPI bus locking. Devices without physical CS pins are unaffected by the cs_change flag issue.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:14:24 UTC

Technical Analysis

The Linux kernel vulnerability in the iio adc ad_sigma_delta driver involved improper handling of the chip select (CS) line during SPI transfers. Specifically, in ad_sigma_delta_single_conversion(), calls to set_mode(AD_SD_MODE_IDLE) and disable_one() were made while keep_cs_asserted was still true, causing SPI transfers to carry cs_change=1 and leaving the CS line permanently asserted after conversion. Additionally, in the error path of ad_sd_buffer_postenable(), failure after entering continuous conversion mode left the device in continuous mode with CS asserted and caused bus_locked to remain true after spi_bus_unlock(), allowing concurrent SPI access without proper locking. The fix moves cleanup calls after clearing keep_cs_asserted and properly resets device mode and bus lock state. Devices lacking physical CS pins are not affected by the cs_change flag issue.

Potential Impact

The vulnerability could cause the SPI chip select line to remain asserted indefinitely, potentially disrupting SPI communication and leaving the device in an unintended continuous conversion mode. Furthermore, improper bus locking could allow concurrent SPI operations without proper synchronization, risking data corruption or undefined behavior in SPI transactions. Devices without physical CS pins are not impacted by the CS assertion issue.

Mitigation Recommendations

A fix has been implemented in the Linux kernel to correct the order of operations in the ad_sigma_delta driver, ensuring the CS line is properly deasserted and bus locking is correctly managed. Users should update to the fixed Linux kernel version containing this patch. Since this is a kernel-level fix, applying the official kernel update is the recommended remediation. Patch status is not explicitly confirmed here; check the vendor or Linux kernel advisory for the exact fixed versions and update guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-8j65-cc62-w2hg
Osv Schema Version
1.4.0
Aliases
["CVE-2026-64501"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a6542069c2644c7f808209c

Added to database: 07/25/2026, 23:08:54 UTC

Last enriched: 07/25/2026, 23:14:24 UTC

Last updated: 07/26/2026, 05:32:00 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses