Description
In the Linux kernel, the following vulnerability has been resolved:

misc: ad525x_dpot: use driver core groups for sysfs files

ad_dpot_probe() creates per-RDAC sysfs files manually and then
optionally creates the command sysfs group. This leaves probe responsible
for rolling back partial sysfs state and makes remove responsible for
matching every file that probe created.

Move the device attributes into driver core dev_groups for the I2C and
SPI drivers and use an is_visible() callback to expose only the
attributes supported by the probed device. With this shape, the driver
core creates the sysfs files only after probe succeeds and removes them
before the remove callback frees the driver data.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Update Kernel
AI Analysis

Impact

The ad525x_dpot driver creates device‑specific sysfs files during probe but relies on the caller to roll back those files if probe fails, and it leaves the removal routine to match every file it created; this design permits inconsistent kernel state when a probe fails or a device is removed, potentially leaving stale sysfs entries that can lead to kernel crashes or instability when accessed.

Affected Systems

All Linux kernel installations that load the ad525x_dpot device driver are potentially vulnerable; no specific kernel version range is specified in the advisory, so any kernel that has not incorporated the committed changes that move the device attributes into driver core dev_groups remains exposed.

Risk and Exploitability

The EPSS score is below 1 percent and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild, but it requires local access to load or probe the driver; the likely attack vector is a local attacker triggering a probe or removal that leaves inconsistent sysfs state, which may cause denial of service or kernel instability.

Generated by OpenCVE AI on September 19, 2026 at 12:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the ad525x_dpot sysfs group fix, which moves device attributes into driver core dev_groups and provides proper cleanup during probe and remove.
  • If an immediate kernel update is not possible, disable the ad525x_dpot driver or unload it so the vulnerable sysfs files are never created.
  • If remnants of the old sysfs entries exist, manually delete them from /sys and ensure no untrusted users can interact with the device during the transition.

Generated by OpenCVE AI on September 19, 2026 at 12:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: misc: ad525x_dpot: use driver core groups for sysfs files ad_dpot_probe() creates per-RDAC sysfs files manually and then optionally creates the command sysfs group. This leaves probe responsible for rolling back partial sysfs state and makes remove responsible for matching every file that probe created. Move the device attributes into driver core dev_groups for the I2C and SPI drivers and use an is_visible() callback to expose only the attributes supported by the probed device. With this shape, the driver core creates the sysfs files only after probe succeeds and removes them before the remove callback frees the driver data.
Title misc: ad525x_dpot: use driver core groups for sysfs files
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:41.052Z

Reserved: 2026-09-17T15:57:05.658Z

Link: CVE-2026-93051

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:58.500

Modified: 2026-09-17T17:17:58.500

Link: CVE-2026-93051

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:15:06Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release