7.8
CVE-2026-80952
- EPSS 0.13%
- Veröffentlicht 11.09.2026 19:42:21
- Zuletzt bearbeitet 14.09.2026 13:18:50
- Erkennungen
i3c: master: Fix info leak and UAF in device unregister path
In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregister path i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before calling device_unregister(). During device_unregister(), device_del() emits a KOBJ_REMOVE uevent and unbinds the driver while the device descriptor is still expected to be valid. As a result, i3c_device_uevent() and a racing modalias_show() can observe a NULL desc and fall back to an uninitialized stack struct i3c_device_info, leaking kernel stack contents in the generated modalias. Driver .remove() callbacks may also encounter an unexpected NULL desc during unbind. Keep desc valid until device_unregister() has completed. Since device_unregister() drops the device reference and may free the device, take an extra reference with get_device() before unregistering. Clear desc afterwards and release the extra reference with put_device(). This preserves the release-time invariant that desc must be NULL while avoiding both the information leak and a potential use-after-free from writing desc after the device has been released.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0
Version <
334cfb5e285cece5dc49fb3fb8ea9b70b2cb5d7e
Status
affected
Version
3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0
Version <
109995153898454c7795c2c299fd0a0b57456a4b
Status
affected
Version
3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0
Version <
c64daaaba08e490c8347ff60aacac4dd51249f91
Status
affected
Version
3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0
Version <
ef72ff6650c4ebf2b444708d84df66db42f262d9
Status
affected
Version
3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0
Version <
c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49
Status
affected
Version
3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0
Version <
94fb9786d67a8f8b899e77381620f86bad94fdf7
Status
affected
Version
3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0
Version <
4837be0f9ac2efe5e83b35a696b6242c473d280c
Status
affected
Version
3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0
Version <
d2c743efd2d1ee64e94324664808f623dd865872
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.0
Status
affected
Version
0
Version <
5.0
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.025 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49
https://git.kernel.org/stable/c/94fb9786d67a8f8b899e77381620f86bad94fdf7
https://git.kernel.org/stable/c/4837be0f9ac2efe5e83b35a696b6242c473d280c
https://git.kernel.org/stable/c/d2c743efd2d1ee64e94324664808f623dd865872
https://git.kernel.org/stable/c/109995153898454c7795c2c299fd0a0b57456a4b
https://git.kernel.org/stable/c/334cfb5e285cece5dc49fb3fb8ea9b70b2cb5d7e
https://git.kernel.org/stable/c/c64daaaba08e490c8347ff60aacac4dd51249f91
https://git.kernel.org/stable/c/ef72ff6650c4ebf2b444708d84df66db42f262d9