Use-after-free in Linux kernel - CVE-2026-89983
Published: September 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the I2C core adapter debugfs directory handling when a write to the new_device sysfs attribute races with adapter removal. A local user can write to the new_device sysfs attribute during adapter removal to cause a denial of service.
Affected software
How to mitigate CVE-2026-89983
External References
- https://git.kernel.org/stable/c/112b3d48084c820bbccf41d9783fd122e3ac4cb0
- https://git.kernel.org/stable/c/1f1bcd4eca6caa3e4258d9a31925112539406eb6
- https://git.kernel.org/stable/c/552836be2d95c688eede6371f85532abe1a71232
- https://git.kernel.org/stable/c/643fb872aa04342d27dbef52b2b3cf3fe71b2c7b
- https://git.kernel.org/stable/c/b15b548d52b43ba8ac4652bc2c7244a8dd1e9622
- https://git.kernel.org/stable/c/dc33a9762538b3250ed6b5644a4d44c748be33a6
- https://git.kernel.org/stable/c/f9094ace03e0a532cc6505d2e97b61ae738da4ed