Description
In the Linux kernel, the following vulnerability has been resolved:

iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling

ams_event_to_channel() may return a pointer past the end of
dev->channels when no matching scan_index is found. This can lead
to invalid memory access in ams_handle_event().

Add a bounds check in ams_event_to_channel() and return NULL when
no channel is found. Also guard the caller to safely handle this
case.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Xilinx AMS Industrial I/O driver contains a flaw in the function that translates an event into a channel. When the event cannot be matched to a scan index, the function returns a pointer that lies past the end of the device’s channel array. The subsequent event handler then dereferences this invalid pointer, which can result in an out‑of‑bounds memory read or write that triggers a kernel Oops and potentially crashes the system. This constitutes a denial of service.

Affected Systems

All Linux kernel installations that include the Xilinx AMS driver are affected. The driver is compiled into the kernel’s IIO subsystem and is enabled on a broad range of embedded boards, development kits, and FPGA platforms that integrate Xilinx’s Analog Mixed‑Signal controller. Any such system running a kernel version prior to the patch does not have the bounds check and is therefore at risk.

Risk and Exploitability

The CVSS score of 7.8 classifies this as a high severity vulnerability. The EPSS score of below 1% indicates that the probability of exploitation is currently low. The case is not listed in the CISA KEV catalog, further suggesting that no widespread exploitation is known. Based on the description, it is inferred that the attack vector is primarily local or privileged, requiring the ability to trigger events on the AMS device. If the device is exposed via a networked interface or an external driver that can be influenced by non‑privileged users, remote exploitation could be possible, but the low EPSS score and lack of KEV listing suggest the risk to availability is moderate with a low expectation of active attacks today.

Generated by OpenCVE AI on August 22, 2026 at 05:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that contains the ams_event_to_channel bounds‑check patch.
  • If an immediate kernel upgrade cannot be performed, blacklist or unload the Xilinx AMS driver so the vulnerable code does not execute.
  • Monitor kernel logs for Oops or BUG messages referencing the AMS driver and apply the security update as soon as it becomes available.

Generated by OpenCVE AI on August 22, 2026 at 05:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
CWE-788

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
CWE-788

Mon, 17 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-788

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-788

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling ams_event_to_channel() may return a pointer past the end of dev->channels when no matching scan_index is found. This can lead to invalid memory access in ams_handle_event(). Add a bounds check in ams_event_to_channel() and return NULL when no channel is found. Also guard the caller to safely handle this case.
Title iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:44:43.931Z

Reserved: 2026-08-09T03:40:39.935Z

Link: CVE-2026-72480

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:22.210

Modified: 2026-08-17T06:19:16.100

Link: CVE-2026-72480

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72480 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T05:45:05Z

Weaknesses