CVE-2026-64279 (GCVE-0-2026-64279)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:52
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
i2c: core: fix adapter deregistration race
Adapters can be looked up by their id using i2c_get_adapter() which
takes a reference to the embedded struct device.
Remove the adapter from the IDR before tearing it down during
deregistration (and on registration failure) to make sure its resources
are not accessed after having been freed (e.g. the device name).
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 35fc37f8188177e3ba3e7f99a6e3300e490e9181 Version: 35fc37f8188177e3ba3e7f99a6e3300e490e9181 Version: 35fc37f8188177e3ba3e7f99a6e3300e490e9181 Version: 35fc37f8188177e3ba3e7f99a6e3300e490e9181 Version: 35fc37f8188177e3ba3e7f99a6e3300e490e9181 Version: 35fc37f8188177e3ba3e7f99a6e3300e490e9181 Version: 35fc37f8188177e3ba3e7f99a6e3300e490e9181 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/i2c/i2c-core-base.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d39282f552dd6c35b9b84b4af78f1198c24f3373",
"status": "affected",
"version": "35fc37f8188177e3ba3e7f99a6e3300e490e9181",
"versionType": "git"
},
{
"lessThan": "11dfa37bf544cc806f21742ca2fd2d841bd7032e",
"status": "affected",
"version": "35fc37f8188177e3ba3e7f99a6e3300e490e9181",
"versionType": "git"
},
{
"lessThan": "9882a9bd74db08e7bae5821a7050627ae92d3380",
"status": "affected",
"version": "35fc37f8188177e3ba3e7f99a6e3300e490e9181",
"versionType": "git"
},
{
"lessThan": "bb234487a447a99315add1b46aa57b72e163e1eb",
"status": "affected",
"version": "35fc37f8188177e3ba3e7f99a6e3300e490e9181",
"versionType": "git"
},
{
"lessThan": "b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3",
"status": "affected",
"version": "35fc37f8188177e3ba3e7f99a6e3300e490e9181",
"versionType": "git"
},
{
"lessThan": "35dbd1f1f603401155cbd3a180bb18e3a3b675b8",
"status": "affected",
"version": "35fc37f8188177e3ba3e7f99a6e3300e490e9181",
"versionType": "git"
},
{
"lessThan": "b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f",
"status": "affected",
"version": "35fc37f8188177e3ba3e7f99a6e3300e490e9181",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/i2c/i2c-core-base.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.31"
},
{
"lessThan": "2.6.31",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "2.6.31",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "2.6.31",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix adapter deregistration race\n\nAdapters can be looked up by their id using i2c_get_adapter() which\ntakes a reference to the embedded struct device.\n\nRemove the adapter from the IDR before tearing it down during\nderegistration (and on registration failure) to make sure its resources\nare not accessed after having been freed (e.g. the device name)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - An attacker reaches the vulnerable lookup through local open/openat calls on /dev/i2c-N and can trigger dynamic-adapter teardown through local usbfs ioctls. No network path directly reaches i2c_get_adapter().\nAC:L - An attacker with access to both device nodes can control both sides by racing parallel I2C opens against repeatable USBDEVFS_DISCONNECT and rebind operations. No victim-controlled timing or uncontrollable condition is required.\nPR:L - i2cdev_open() and the usbfs disconnect path impose device-node DAC, LSM, and device-cgroup checks but no capability requirement. A regular user granted I2C and USB-device access can trigger the race without init-namespace root.\nUI:N - The attacker can initiate the adapter lookup, software disconnect, and subsequent stale-adapter operations directly. No separate victim action is required.\nS:U - Exploitation corrupts or executes code within the same host kernel security authority. This is ordinary local kernel privilege escalation rather than a VM, IOMMU, or other scope-boundary escape.\nC:H - The race can return an adapter after its embedded device resources have been released, followed by freeing of the enclosing dynamic-adapter allocation. Reclaiming this heap object permits attacker-influenced pointer dereferences and potential arbitrary kernel-memory disclosure.\nI:H - The stale adapter contains algorithm and locking function pointers, while I2C ioctls also write mutable adapter fields. Heap reclamation can therefore provide memory-corruption and control-flow-hijacking primitives leading to kernel code execution.\nA:H - Refcount resurrection, stale device-resource accesses, and dereferences through a freed adapter can produce kernel warnings, oopses, or panics. An attacker controlling disconnect and rebind can repeat the trigger."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:52:34.328Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d39282f552dd6c35b9b84b4af78f1198c24f3373"
},
{
"url": "https://git.kernel.org/stable/c/11dfa37bf544cc806f21742ca2fd2d841bd7032e"
},
{
"url": "https://git.kernel.org/stable/c/9882a9bd74db08e7bae5821a7050627ae92d3380"
},
{
"url": "https://git.kernel.org/stable/c/bb234487a447a99315add1b46aa57b72e163e1eb"
},
{
"url": "https://git.kernel.org/stable/c/b6d2af6fe9c1f5ec0484536753c979cbd40a8ac3"
},
{
"url": "https://git.kernel.org/stable/c/35dbd1f1f603401155cbd3a180bb18e3a3b675b8"
},
{
"url": "https://git.kernel.org/stable/c/b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f"
}
],
"title": "i2c: core: fix adapter deregistration race",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64279",
"datePublished": "2026-07-25T08:49:23.145Z",
"dateReserved": "2026-07-19T15:36:31.777Z",
"dateUpdated": "2026-08-17T04:52:34.328Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…