Description
In the Linux kernel, the following vulnerability has been resolved:

i2c: mux: Fix channel node leak on adapter add failure

i2c_mux_add_adapter() takes a reference to the Device Tree channel node
before registering the new adapter. If adapter registration fails, the
error path frees the private data without dropping that reference.

Release the channel node before freeing the private data.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion (Denial of Service)
Action: Patch
AI Analysis

Impact

The vulnerability is in the i2c mux subsystem of the Linux kernel. When an adapter registration fails, the driver frees the private data without dropping a reference to the Device Tree channel node that was previously taken. This results in a memory leak that can grow until kernel memory is exhausted, potentially leading to instability or a denial‑of‑service condition. The weakness is a classic resource‑management flaw that affects system availability if the leak can be repeatedly triggered.

Affected Systems

All Linux kernel builds that include the i2c mux driver and contain the unpatched code are at risk. No specific releases or versions are identified, so any kernel containing this code path before the fix is vulnerable.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no CVSS score is supplied. Because the flaw requires the kernel to attempt an adapter registration that fails, it is likely exploitable only from a local privileged context or by malicious firmware that manipulates the device tree. Given the low exploitation likelihood, the overall risk remains moderate relative to higher‑impact flaws, but the potential for resource exhaustion warrants prompt patching.

Generated by OpenCVE AI on September 18, 2026 at 08:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the commit fixing the i2c mux leak.
  • If a kernel upgrade is not immediately possible, isolate or disable the affected i2c devices via device tree overrides or configuration changes to prevent the faulty adapter registration.
  • Set up monitoring of kernel memory usage to detect abnormal growth and trigger alerts or automatic reboots when thresholds are exceeded.

Generated by OpenCVE AI on September 18, 2026 at 08:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i2c: mux: Fix channel node leak on adapter add failure i2c_mux_add_adapter() takes a reference to the Device Tree channel node before registering the new adapter. If adapter registration fails, the error path frees the private data without dropping that reference. Release the channel node before freeing the private data.
Title i2c: mux: Fix channel node leak on adapter add failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:58.747Z

Reserved: 2026-09-11T19:38:34.779Z

Link: CVE-2026-89982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:09.147

Modified: 2026-09-16T11:17:09.147

Link: CVE-2026-89982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:15:06Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime