SB2026092598 - Use-after-free in Linux kernel i3c driver
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-93283)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in i3c_master_register_new_i3c_devs() when handling a device_register() failure. A local user can trigger a device registration failure followed by device unregistration to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/20a2b6df91fd782ef2ff551febef594d0b46a9a7
- https://git.kernel.org/stable/c/5bf498623f8397d45f85f14cd631c5e5a565c2fb
- https://git.kernel.org/stable/c/6ecf17bf5fe8da51a6e3fc9e03a76898fcc5c6cf
- https://git.kernel.org/stable/c/74be657d98a8d684c0475f3cbd450ef2a30ffc73
- https://git.kernel.org/stable/c/7ef12e1dd06e442eebf370f6e53c41bd056d0f22
- https://git.kernel.org/stable/c/7f8e2c4f3704d9774bb26b49b1ad6a60ae57d4a0
- https://git.kernel.org/stable/c/a14dbdf471001dd0601b0c491184990c178a199c
- https://git.kernel.org/stable/c/d22ad96f1a0c89e0ba66a2facc7430f0923919e3