Impact
An out‑of‑bounds, use‑after‑free bug in the I²C core driver allows a write to the new_device debugfs file while an adapter is being removed to cause the kernel to dereference freed memory. The crash manifests as a KASAN error and can bring the system down or hang waiting for a completion. The flaw can be triggered by a local user who can write to the new_device attribute, potentially resulting in a denial of service or an unsafe kernel state.
Affected Systems
All Linux kernel releases that do not contain the commit that fixes the I²C debugfs use‑after‑free. The issue is present in every kernel that exposes the new_device sysfs entry for I²C adapters, regardless of distribution, because the vulnerability resides in the core kernel source. Mitigating this requires patching or upgrading the kernel to a version that includes the fix.
Risk and Exploitability
The risk of exploitation is low based on an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog, and only a local attack is possible, requiring write access to the debugfs entry. Although the flaw leads to a critical impairment of system availability, the low add‑on exploitation probability and lack of remote reachability mitigate its threat compared to high‑severity remote vulnerabilities.
OpenCVE Enrichment
Debian DLA
Debian DSA