Use-after-free in Linux kernel - CVE-2026-93283
Published: September 25, 2026
Vulnerability identifier: #VU152122
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93283
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in i3c_master_register_new_i3c_devs() when handling a device_register() failure. A local user can trigger a device registration failure followed by device unregistration to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-93283
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/20a2b6df91fd782ef2ff551febef594d0b46a9a7
- https://git.kernel.org/stable/c/5bf498623f8397d45f85f14cd631c5e5a565c2fb
- https://git.kernel.org/stable/c/6ecf17bf5fe8da51a6e3fc9e03a76898fcc5c6cf
- https://git.kernel.org/stable/c/74be657d98a8d684c0475f3cbd450ef2a30ffc73
- https://git.kernel.org/stable/c/7ef12e1dd06e442eebf370f6e53c41bd056d0f22
- https://git.kernel.org/stable/c/7f8e2c4f3704d9774bb26b49b1ad6a60ae57d4a0
- https://git.kernel.org/stable/c/a14dbdf471001dd0601b0c491184990c178a199c
- https://git.kernel.org/stable/c/d22ad96f1a0c89e0ba66a2facc7430f0923919e3