Description
In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Fix DM I2C teardown race

DM I2C adapters can remain visible to userspace while DM teardown is
already in progress. A concurrent i2c-dev transfer may then enter
amdgpu_dm_i2c_xfer() after the backing DM state has been torn down,
leading to a NULL pointer dereference.

Create a devres group around the DM I2C adapter lifetime and release it
at the start of dm_hw_fini(), before HPD, IRQ, and DM state are torn
down. This removes the I2C adapters first and waits for in-flight users
to drain before the structures used by amdgpu_dm_i2c_xfer() disappear.

This fixes a teardown ordering race seen during device removal:

BUG: kernel NULL pointer dereference
RIP: amdgpu_dm_i2c_xfer+0x122/0x1c0 [amdgpu]
Call Trace:
__i2c_transfer
i2c_transfer
i2cdev_ioctl_rdwr
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Crash)
Action: Patch
AI Analysis

Impact

In the Linux kernel, a race condition in the AMDGPU display driver can cause a NULL pointer dereference. While a device manager (DM) teardown is underway, DM I2C adapters remain exposed to userspace. If an in‑flight i2c‑dev transfer is issued during this window, the kernel calls amdgpu_dm_i2c_xfer() after the underlying DM state has been dismantled, dereferencing a NULL pointer. The crash results in a kernel panic, effectively denying service to the affected system and potentially allowing a local attacker to trigger a privilege‑escalation exploit or disrupt critical services.

Affected Systems

The flaw affects the generic Linux kernel that includes the AMDGPU GPU drivers, particularly those where the DM I2C adapter lifespan was not properly scoped. No specific kernel version range is listed in the advisory, so any kernel build with the unpatched AMDGPU driver could be vulnerable until the patch that introduces a devres group around the DM I2C adapter is applied.

Risk and Exploitability

The EPSS score is below 1 %, indicating a very low likelihood of widespread exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. Because the issue requires a concurrent i2c‑dev request during device removal, the practical attack vector is likely local or involves privileged users with access to the device. If exploited, the outcome is a kernel crash, which can serve as a foothold for further attacks or, at minimum, cause an outage.

Generated by OpenCVE AI on September 19, 2026 at 06:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel patch that adds a devres group around the DM I2C adapter and releases it during dm_hw_fini().
  • Reboot the system after applying the patch to ensure the new driver code is active.
  • Until the patch is applied, restrict i2c‑dev access for untrusted users or temporarily disable the AMDGPU drivers on machines that are not in critical use.

Generated by OpenCVE AI on September 19, 2026 at 06:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix DM I2C teardown race DM I2C adapters can remain visible to userspace while DM teardown is already in progress. A concurrent i2c-dev transfer may then enter amdgpu_dm_i2c_xfer() after the backing DM state has been torn down, leading to a NULL pointer dereference. Create a devres group around the DM I2C adapter lifetime and release it at the start of dm_hw_fini(), before HPD, IRQ, and DM state are torn down. This removes the I2C adapters first and waits for in-flight users to drain before the structures used by amdgpu_dm_i2c_xfer() disappear. This fixes a teardown ordering race seen during device removal: BUG: kernel NULL pointer dereference RIP: amdgpu_dm_i2c_xfer+0x122/0x1c0 [amdgpu] Call Trace: __i2c_transfer i2c_transfer i2cdev_ioctl_rdwr
Title drm/amd/display: Fix DM I2C teardown race
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:52.971Z

Reserved: 2026-09-17T15:57:05.660Z

Link: CVE-2026-93068

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:00.647

Modified: 2026-09-17T17:18:00.647

Link: CVE-2026-93068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:15:04Z

Weaknesses