Description
In the Linux kernel, the following vulnerability has been resolved:

i3c: master: Fix use-after-free of master->this

sysfs attribute callbacks for the master controller device dereference
master->this. However, master->this is freed in
i3c_master_detach_free_devs() before the master device itself is
released.

As a result, sysfs accesses can dereference a freed master->this
pointer, leading to a use-after-free.

Keep master->this alive until i3c_masterdev_release(), which is called
after the master device and its sysfs state are being torn down. Do not
free master->this as part of the normal device detach path.

On the error path in i3c_master_set_info(), reset master->this and
bus.cur_master to NULL before freeing the allocated device.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in I3C master controller sysfs callbacks
Action: Update Kernel
AI Analysis

Impact

The kernel defect occurs when sysfs attribute callbacks for an I3C master controller access the master->this structure after it has been freed by i3c_master_detach_free_devs. Because master->this is dereferenced after its memory has been released, a dangling pointer is used, which can corrupt memory and potentially allow an attacker to execute arbitrary code at the kernel level. This is a classic Use‑After‑Free flaw and directly compromises the integrity and confidentiality of the system.

Affected Systems

The vulnerability affects the Linux kernel wherever the I3C master controller subsystem is present. Affected versions are not enumerated, so every kernel build that includes the unpatched I3C master code is potentially vulnerable. The issue is associated with the Linux vendor.

Risk and Exploitability

The EPSS score of less than 1% indicates that the defect has an extremely low probability of being exploited in the wild at the current time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Because a use‑after‑free can lead to arbitrary kernel code execution, the potential impact is high if an attacker can trigger the vulnerable sysfs path. Inferred attack vectors suggest a local or privileged user could trigger the flaw through sysfs interaction, though the exact prerequisites are not detailed in the advisory. The lack of a CVSS score in the provided data means the community has not yet quantified the severity, but the nature of the flaw suggests severe risk if exploited.

Generated by OpenCVE AI on September 19, 2026 at 08:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a revision that contains the upstream fix for the I3C master use‑after‑free issue.
  • If a standard kernel update is unavailable, recompile the kernel with the specific patch commit that preserves master->this until the device is fully torn down.
  • As an interim measure, monitor sysfs activity for the I3C master device and consider disabling the I3C master interface or removing its sysfs entries if the vulnerability cannot be immediately remediated.

Generated by OpenCVE AI on September 19, 2026 at 08:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix use-after-free of master->this sysfs attribute callbacks for the master controller device dereference master->this. However, master->this is freed in i3c_master_detach_free_devs() before the master device itself is released. As a result, sysfs accesses can dereference a freed master->this pointer, leading to a use-after-free. Keep master->this alive until i3c_masterdev_release(), which is called after the master device and its sysfs state are being torn down. Do not free master->this as part of the normal device detach path. On the error path in i3c_master_set_info(), reset master->this and bus.cur_master to NULL before freeing the allocated device.
Title i3c: master: Fix use-after-free of master->this
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:57:05.718Z

Reserved: 2026-09-17T16:02:15.092Z

Link: CVE-2026-93200

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:16.297

Modified: 2026-10-03T11:17:46.447

Link: CVE-2026-93200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:15:16Z

Weaknesses