CVE-2026-46282

In the Linux kernel, the following vulnerability has been resolved: iio: frequency: admv1013: fix NULL pointer dereference on str When device_property_read_string() fails, str is left uninitialized but the code falls through to strcmp(str, ...), dereferencing a garbage pointer. Replace manual read/strcmp with device_property_match_property_string() and consolidate the SE mode enums into a single sequential enum, mapping to hardware register values via a switch consistent with other bitfields in the driver. Several cleanup patches have been applied to this driver recently so this will need a manual backport.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: iio: frequency: admv1013: corrección de desreferencia de puntero NULL en str Cuando device_property_read_string() falla, str queda sin inicializar, pero el código continúa hacia strcmp(str, ...), desreferenciando un puntero basura. Reemplazar la lectura/strcmp manual con device_property_match_property_string() y consolidar las enumeraciones de modo SE en una única enumeración secuencial, mapeando a valores de registro de hardware a través de un switch consistente con otros campos de bits en el controlador. Varios parches de limpieza han sido aplicados a este controlador recientemente, por lo que esto requerirá un backport manual.

08 Jul 2026, 15:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux linux Kernel
Linux
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-476
References () https://git.kernel.org/stable/c/2dc8d26690bf4e7226409563221c37bc095c94ff - () https://git.kernel.org/stable/c/2dc8d26690bf4e7226409563221c37bc095c94ff - Patch
References () https://git.kernel.org/stable/c/3a9d8ec2051c2d80158ed7bded5e158c42870037 - () https://git.kernel.org/stable/c/3a9d8ec2051c2d80158ed7bded5e158c42870037 - Patch
References () https://git.kernel.org/stable/c/5e9f1bad26df3d3afb3cbbfa408b6d6e809708ac - () https://git.kernel.org/stable/c/5e9f1bad26df3d3afb3cbbfa408b6d6e809708ac - Patch
References () https://git.kernel.org/stable/c/aac0a51b16700b403a55b67ba495de021db78763 - () https://git.kernel.org/stable/c/aac0a51b16700b403a55b67ba495de021db78763 - Patch

08 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 17:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-46282

Mitre link : CVE-2026-46282

CVE.ORG link : CVE-2026-46282


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference