Description
In the Linux kernel, the following vulnerability has been resolved:

drm/panel-edp: fix i2c adapter leak on probe failure

Make sure to drop the i2c adapter reference on probe failure (e.g.
probe deferral) and on driver unbind also if a devicetree redundantly
uses the 'ddc-i2c-bus' property to point to the aux ddc bus.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion via I2C Adapter Leak
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Linux kernel’s DRM panel EDP driver keeps a reference to an I2C adapter when the probe fails or when the device tree incorrectly uses the ‘ddc‑i2c‑bus’ property, leaving the adapter allocated longer than necessary. This leak can accumulate over time, causing kernel reference counts and memory allocation to grow until the I2C subsystem is unable to function properly, which is a direct drain of kernel resources.

Affected Systems

All Linux kernel deployments that include the DRM panel EDP driver are potentially affected. No specific version is listed in the advisory; the issue was addressed in commit 0259846b15a665c6762a86b3fa0eb8b674b35d1c and appears in subsequent kernel releases.

Risk and Exploitability

No CVSS score has been published for this issue. The EPSS score is below 1%, indicating a very low probability of exploitation in the wild. The vulnerability has not appeared in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require an attacker to have the ability to repeatedly trigger probe failures or alter device tree configuration, which typically implies local or privileged access.

Generated by OpenCVE AI on September 18, 2026 at 09:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit fixing the I2C adapter leak (the patch referenced in the advisory or any later stable kernel release).
  • If you control device tree configurations, ensure that the ‘ddc‑i2c‑bus’ property points to a valid aux DDC bus and that no redundant or incorrect references are present in the device tree.
  • Monitor kernel logs and system behavior for repeated I2C adapter allocation failures or an unexpected increase in I2C adapter reference counts, and take corrective action if abnormal resource usage is observed.

Generated by OpenCVE AI on September 18, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/panel-edp: fix i2c adapter leak on probe failure Make sure to drop the i2c adapter reference on probe failure (e.g. probe deferral) and on driver unbind also if a devicetree redundantly uses the 'ddc-i2c-bus' property to point to the aux ddc bus.
Title drm/panel-edp: fix i2c adapter leak on probe failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:30:56.587Z

Reserved: 2026-09-11T19:38:34.768Z

Link: CVE-2026-89824

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:48.993

Modified: 2026-09-16T11:16:48.993

Link: CVE-2026-89824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses

No weakness.