SB2026082891 - Use-after-free in Linux kernel i2c busses driver
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-80680)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the amd mp2 i2c platform driver callback handling when i2c_add_adapter() fails during adapter registration. A local user can trigger adapter registration failure and subsequent callback dereference to cause a denial of service.
The stale pointer may be dereferenced from IRQ and system-sleep callbacks after the platform I2C context has been freed.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1883a09a37fed497b9efacf736c23624a472246b
- https://git.kernel.org/stable/c/2f7789b3a9628819ebf90bcba8f9da3c139f8687
- https://git.kernel.org/stable/c/4786d4d70dcd1e6b7e044f2348e00f201947b69c
- https://git.kernel.org/stable/c/82048795242f04275a3f49ffc66ad851b6120954
- https://git.kernel.org/stable/c/8bf719659406e4a1b56d441e0c7da2085d891d96
- https://git.kernel.org/stable/c/9142a3dcff0d80a3a24ce159aee19ddc869d9784
- https://git.kernel.org/stable/c/b7c2c5c8868737926410b93d1223ada17625ead3
- https://git.kernel.org/stable/c/cf107c5983dc70fcf932a305581a5f976d908ff1