Use-after-free in Linux kernel - CVE-2026-80680
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the amd mp2 i2c platform driver callback handling when i2c_add_adapter() fails during adapter registration. A local user can trigger adapter registration failure and subsequent callback dereference to cause a denial of service.
The stale pointer may be dereferenced from IRQ and system-sleep callbacks after the platform I2C context has been freed.
Affected software
How to mitigate CVE-2026-80680
External References
- https://git.kernel.org/stable/c/1883a09a37fed497b9efacf736c23624a472246b
- https://git.kernel.org/stable/c/2f7789b3a9628819ebf90bcba8f9da3c139f8687
- https://git.kernel.org/stable/c/4786d4d70dcd1e6b7e044f2348e00f201947b69c
- https://git.kernel.org/stable/c/82048795242f04275a3f49ffc66ad851b6120954
- https://git.kernel.org/stable/c/8bf719659406e4a1b56d441e0c7da2085d891d96
- https://git.kernel.org/stable/c/9142a3dcff0d80a3a24ce159aee19ddc869d9784
- https://git.kernel.org/stable/c/b7c2c5c8868737926410b93d1223ada17625ead3
- https://git.kernel.org/stable/c/cf107c5983dc70fcf932a305581a5f976d908ff1