SB20260916126 - Use-after-free in Linux kernel i2c driver
Published: September 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-89983)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the I2C core adapter debugfs directory handling when a write to the new_device sysfs attribute races with adapter removal. A local user can write to the new_device sysfs attribute during adapter removal to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/112b3d48084c820bbccf41d9783fd122e3ac4cb0
- https://git.kernel.org/stable/c/1f1bcd4eca6caa3e4258d9a31925112539406eb6
- https://git.kernel.org/stable/c/552836be2d95c688eede6371f85532abe1a71232
- https://git.kernel.org/stable/c/643fb872aa04342d27dbef52b2b3cf3fe71b2c7b
- https://git.kernel.org/stable/c/b15b548d52b43ba8ac4652bc2c7244a8dd1e9622
- https://git.kernel.org/stable/c/dc33a9762538b3250ed6b5644a4d44c748be33a6
- https://git.kernel.org/stable/c/f9094ace03e0a532cc6505d2e97b61ae738da4ed