In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted and state leaks In… (CVE-2026-64501)
A vulnerability in the Linux kernel's iio adc ad_sigma_delta driver caused the chip select (CS) line to remain asserted and allowed state leaks during SPI transfers. This occurred because certain cleanup calls were made while the CS line was still held asserted, leading to improper SPI bus state and potential concurrent access issues. The issue was fixed by adjusting the order of operations to clear the CS assertion before cleanup calls and properly managing SPI bus locking. Devices without physical CS pins are unaffected by the cs_change flag issue.
AI Analysis
Technical Summary
The Linux kernel vulnerability in the iio adc ad_sigma_delta driver involved improper handling of the chip select (CS) line during SPI transfers. Specifically, in ad_sigma_delta_single_conversion(), calls to set_mode(AD_SD_MODE_IDLE) and disable_one() were made while keep_cs_asserted was still true, causing SPI transfers to carry cs_change=1 and leaving the CS line permanently asserted after conversion. Additionally, in the error path of ad_sd_buffer_postenable(), failure after entering continuous conversion mode left the device in continuous mode with CS asserted and caused bus_locked to remain true after spi_bus_unlock(), allowing concurrent SPI access without proper locking. The fix moves cleanup calls after clearing keep_cs_asserted and properly resets device mode and bus lock state. Devices lacking physical CS pins are not affected by the cs_change flag issue.
Potential Impact
The vulnerability could cause the SPI chip select line to remain asserted indefinitely, potentially disrupting SPI communication and leaving the device in an unintended continuous conversion mode. Furthermore, improper bus locking could allow concurrent SPI operations without proper synchronization, risking data corruption or undefined behavior in SPI transactions. Devices without physical CS pins are not impacted by the CS assertion issue.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to correct the order of operations in the ad_sigma_delta driver, ensuring the CS line is properly deasserted and bus locking is correctly managed. Users should update to the fixed Linux kernel version containing this patch. Since this is a kernel-level fix, applying the official kernel update is the recommended remediation. Patch status is not explicitly confirmed here; check the vendor or Linux kernel advisory for the exact fixed versions and update guidance.
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted and state leaks In… (CVE-2026-64501)
Description
A vulnerability in the Linux kernel's iio adc ad_sigma_delta driver caused the chip select (CS) line to remain asserted and allowed state leaks during SPI transfers. This occurred because certain cleanup calls were made while the CS line was still held asserted, leading to improper SPI bus state and potential concurrent access issues. The issue was fixed by adjusting the order of operations to clear the CS assertion before cleanup calls and properly managing SPI bus locking. Devices without physical CS pins are unaffected by the cs_change flag issue.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel vulnerability in the iio adc ad_sigma_delta driver involved improper handling of the chip select (CS) line during SPI transfers. Specifically, in ad_sigma_delta_single_conversion(), calls to set_mode(AD_SD_MODE_IDLE) and disable_one() were made while keep_cs_asserted was still true, causing SPI transfers to carry cs_change=1 and leaving the CS line permanently asserted after conversion. Additionally, in the error path of ad_sd_buffer_postenable(), failure after entering continuous conversion mode left the device in continuous mode with CS asserted and caused bus_locked to remain true after spi_bus_unlock(), allowing concurrent SPI access without proper locking. The fix moves cleanup calls after clearing keep_cs_asserted and properly resets device mode and bus lock state. Devices lacking physical CS pins are not affected by the cs_change flag issue.
Potential Impact
The vulnerability could cause the SPI chip select line to remain asserted indefinitely, potentially disrupting SPI communication and leaving the device in an unintended continuous conversion mode. Furthermore, improper bus locking could allow concurrent SPI operations without proper synchronization, risking data corruption or undefined behavior in SPI transactions. Devices without physical CS pins are not impacted by the CS assertion issue.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to correct the order of operations in the ad_sigma_delta driver, ensuring the CS line is properly deasserted and bus locking is correctly managed. Users should update to the fixed Linux kernel version containing this patch. Since this is a kernel-level fix, applying the official kernel update is the recommended remediation. Patch status is not explicitly confirmed here; check the vendor or Linux kernel advisory for the exact fixed versions and update guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8j65-cc62-w2hg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64501"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a6542069c2644c7f808209c
Added to database: 07/25/2026, 23:08:54 UTC
Last enriched: 07/25/2026, 23:14:24 UTC
Last updated: 07/26/2026, 05:32:00 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.