Unrated severityNVD Advisory· Published Jun 8, 2026
CVE-2026-46282
CVE-2026-46282
Description
In the Linux kernel, the following vulnerability has been resolved:
iio: frequency: admv1013: fix NULL pointer dereference on str
When device_property_read_string() fails, str is left uninitialized but the code falls through to strcmp(str, ...), dereferencing a garbage pointer. Replace manual read/strcmp with device_property_match_property_string() and consolidate the SE mode enums into a single sequential enum, mapping to hardware register values via a switch consistent with other bitfields in the driver.
Several cleanup patches have been applied to this driver recently so this will need a manual backport.
Affected products
4- osv-coords2 versions
>= 5.17.0, < 6.12.86+ 1 more
- (no CPE)range: >= 5.17.0, < 6.12.86
- (no CPE)range: < 7.0.12-1.1
Patches
Vulnerability mechanics
References
4News mentions
1- Google Android SDK: 10 Linux Kernel Vulnerabilities Disclosed TogetherVypr Intelligence · Jun 8, 2026