Description
In the Linux kernel, the following vulnerability has been resolved:

i2c: core: fix debugfs UAF on adapter removal

i2c_del_adapter() frees the adapter's debugfs directory before it
unregisters the adapter device, but the new_device sysfs attribute
stays writable until device_del(). A write racing with removal still
reaches i2c_device_probe(), which passes the freed adap->debugfs to
debugfs_create_dir() as the new client's parent:

BUG: KASAN: slab-use-after-free in lookup_noperm_common+0x407/0x430
Read of size 4 at addr ffff88803ef87810 by task syz.0.61/6090
lookup_noperm_common+0x407/0x430
simple_start_creating+0x9c/0x110
debugfs_start_creating+0xdb/0x1a0
debugfs_create_dir+0x24/0x350
i2c_device_probe+0x814/0xbf0

It's technically possible to create a client after i2c_deregister_clients
has run. That client will never be unregistered and make
wait_for_completion hang.

Close the window by removing the new_device attribute at the start of
i2c_del_adapter(). device_remove_file() will drain any clients left.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash or hang)
Action: Patch Immediately
AI Analysis

Impact

An out‑of‑bounds, use‑after‑free bug in the I²C core driver allows a write to the new_device debugfs file while an adapter is being removed to cause the kernel to dereference freed memory. The crash manifests as a KASAN error and can bring the system down or hang waiting for a completion. The flaw can be triggered by a local user who can write to the new_device attribute, potentially resulting in a denial of service or an unsafe kernel state.

Affected Systems

All Linux kernel releases that do not contain the commit that fixes the I²C debugfs use‑after‑free. The issue is present in every kernel that exposes the new_device sysfs entry for I²C adapters, regardless of distribution, because the vulnerability resides in the core kernel source. Mitigating this requires patching or upgrading the kernel to a version that includes the fix.

Risk and Exploitability

The risk of exploitation is low based on an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog, and only a local attack is possible, requiring write access to the debugfs entry. Although the flaw leads to a critical impairment of system availability, the low add‑on exploitation probability and lack of remote reachability mitigate its threat compared to high‑severity remote vulnerabilities.

Generated by OpenCVE AI on September 17, 2026 at 22:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an updated kernel that includes the i2c: core: fix debugfs UAF on adapter removal commit, or rebuild the kernel with the patch applied directly from the provided git commit references.
  • If an immediate kernel upgrade is not feasible, permissively remove or restrict the new_device debugfs file for existing I²C adapters by changing its ownership or permissions to block write access, thereby eliminating the race condition that triggers the use‑after‑free.
  • After disabling the debugfs interface or applying the kernel patch, reboot the system to ensure all stale clients are purged and the kernel’s completion objects are correctly drained.

Generated by OpenCVE AI on September 17, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix debugfs UAF on adapter removal i2c_del_adapter() frees the adapter's debugfs directory before it unregisters the adapter device, but the new_device sysfs attribute stays writable until device_del(). A write racing with removal still reaches i2c_device_probe(), which passes the freed adap->debugfs to debugfs_create_dir() as the new client's parent: BUG: KASAN: slab-use-after-free in lookup_noperm_common+0x407/0x430 Read of size 4 at addr ffff88803ef87810 by task syz.0.61/6090 lookup_noperm_common+0x407/0x430 simple_start_creating+0x9c/0x110 debugfs_start_creating+0xdb/0x1a0 debugfs_create_dir+0x24/0x350 i2c_device_probe+0x814/0xbf0 It's technically possible to create a client after i2c_deregister_clients has run. That client will never be unregistered and make wait_for_completion hang. Close the window by removing the new_device attribute at the start of i2c_del_adapter(). device_remove_file() will drain any clients left.
Title i2c: core: fix debugfs UAF on adapter removal
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:59.461Z

Reserved: 2026-09-11T19:38:34.779Z

Link: CVE-2026-89983

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:09.270

Modified: 2026-09-16T11:17:09.270

Link: CVE-2026-89983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:00:13Z

Weaknesses