Description
In the Linux kernel, the following vulnerability has been resolved:

iio: dac: ad5686: missing NULL check on match data

Verify that chip_info pointer is not NULL. If a user binds the driver
using driver_override via sysfs with a device name not present in the
id_table or of_match_table, match data will be NULL.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A kernel driver for the AD5686 digital‑to‑analog converter performs a NULL check on its match data pointer. If an attacker exploits the driver_override mechanism via sysfs with a nonexistent device name, the match data becomes NULL and the driver dereferences it. This causes an uncontrolled kernel dereference that can crash the system. The likely attack vector is a local user writing to sysfs, and the immediate impact is a denial of service, as the kernel may panic or reset, requiring a reboot to restore service. No confidential data is disclosed and no persistent attacker advantage is gained beyond destabilizing the host.

Affected Systems

All Linux kernel installations that lack the fix for the AD5686 DAC driver, i.e. any kernel before the patch introduced in commit cdaa9cb. The vulnerability applies across all vendor builds of the Linux kernel that include this driver module.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local write access to sysfs, and a determined user can trigger a kernel crash. The CVSS score is not provided, but the presence of an unhandled NULL dereference, together with the ability to invoke it locally, places the risk at moderate to high if the attacker can access sysfs. Mitigation through kernel update or restricting sysfs write permissions would eliminate the risk.

Generated by OpenCVE AI on September 19, 2026 at 09:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that contains the fixed driver code.
  • If updating the kernel is not immediately possible, remove or modify any custom driver_override entries for the ad5686 device and review sysfs write permissions to limit them to root only.
  • Disable the driver_override option in the kernel configuration or remove the sysfs aliases that expose it.

Generated by OpenCVE AI on September 19, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-690

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: iio: dac: ad5686: missing NULL check on match data Verify that chip_info pointer is not NULL. If a user binds the driver using driver_override via sysfs with a device name not present in the id_table or of_match_table, match data will be NULL.
Title iio: dac: ad5686: missing NULL check on match data
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:32.132Z

Reserved: 2026-09-17T15:57:05.657Z

Link: CVE-2026-93038

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:56.877

Modified: 2026-09-17T17:17:56.877

Link: CVE-2026-93038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:30:07Z

Weaknesses
  • CWE-690

    Unchecked Return Value to NULL Pointer Dereference