In the Linux kernel, the following vulnerability has been resolved:
iio: adc: adsigmadelta: fix clearpendingevent for registerless devices
adsigmadeltaclearpendingevent() falls through to the status register read path for devices with hasregisters = false and no rdygpiod. For such devices, adsdreadreg() skips the address byte entirely and clocks raw MISO bytes with no address phase — making it byte-for-byte identical to reading conversion data. If a pending conversion result is present, this partially consumes it and corrupts the data stream for the subsequent adsdreadreg() call in adsigmadeltasingle_conversion().
Furthermore, with numresetclks = 0 on these devices, datareadlen evaluates to 0. If the clocked byte has bit 7 clear, pendingevent is set and the code attempts memset(data + 2, 0xff, 0 - 1), overflowing to SIZE_MAX and corrupting the heap.
Fix by returning 0 immediately when neither rdygpiod nor hasregisters is set. This is safe for all current registerless devices: ad7191 and ad7780 (with powerdown GPIO) are reset between conversions by CS deassertion, so there is no stale result to drain; ad7780 (without powerdown GPIO) and max11205 are continuously-converting and cycle ~DRDY at the output data rate regardless of whether the previous result was read, so the next falling edge fires naturally.
A future registerless device that holds ~DRDY asserted until data is read would be broken by this early return and would require either num_resetclks set or a rdy-gpio.
The same heap corruption is reachable on any device with rdygpiod set but numresetclks = 0: if the GPIO indicates a pending event, the drain path executes memset(data + 2, 0xff, 0 - 1) regardless of hasregisters. Add an explicit datareadlen == 0 guard after the pending event check; the stale result is then consumed by the first adsdreadreg() call in adsigmadeltasingleconversion().
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64502.json"
}