CVE-2026-80952
Received Received - Intake

Use-After-Free and Info Leak in Linux Kernel i3c Master

Vulnerability report for CVE-2026-80952, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregister path i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before calling device_unregister(). During device_unregister(), device_del() emits a KOBJ_REMOVE uevent and unbinds the driver while the device descriptor is still expected to be valid. As a result, i3c_device_uevent() and a racing modalias_show() can observe a NULL desc and fall back to an uninitialized stack struct i3c_device_info, leaking kernel stack contents in the generated modalias. Driver .remove() callbacks may also encounter an unexpected NULL desc during unbind. Keep desc valid until device_unregister() has completed. Since device_unregister() drops the device reference and may free the device, take an extra reference with get_device() before unregistering. Clear desc afterwards and release the extra reference with put_device(). This preserves the release-time invariant that desc must be NULL while avoiding both the information leak and a potential use-after-free from writing desc after the device has been released.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a use-after-free (UAF) and information leak in the I3C device unregister path. The issue occurs when i3c_master_unregister_i3c_devs() clears the device descriptor before calling device_unregister(), leading to a race condition where driver callbacks or uevent handlers may access invalid memory. This can leak kernel stack data or cause crashes.

Detection Guidance

This vulnerability is specific to the Linux kernel's I3C subsystem and requires kernel-level detection. It cannot be detected via network scans or standard commands. Check kernel logs for I3C-related errors or warnings using dmesg | grep i3c or journalctl -k | grep i3c. Ensure your kernel version includes the fix by running uname -r and comparing against patched versions.

Impact Analysis

If exploited, this flaw could allow an attacker to leak sensitive kernel memory or trigger a system crash by causing a use-after-free condition. This may lead to privilege escalation or denial-of-service attacks on affected systems running vulnerable Linux kernels.

Compliance Impact

This vulnerability involves an information leak and potential use-after-free in the Linux kernel's I3C device handling. While it does not directly relate to data protection or privacy standards like GDPR or HIPAA, such kernel vulnerabilities could indirectly impact compliance by exposing sensitive system information or enabling unauthorized access if exploited.

Mitigation Strategies

Update your Linux kernel to a version that includes the fix for CVE-2026-80952. This typically involves running your system's package manager update command, such as sudo apt update && sudo apt upgrade for Debian-based systems or sudo yum update for RHEL-based systems. Reboot the system after applying the update to ensure the patched kernel is active.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80952. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart