{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80952","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.804Z","datePublished":"2026-09-11T19:42:21.868Z","dateUpdated":"2026-09-14T11:59:08.606Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:08.606Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: Fix info leak and UAF in device unregister path\n\ni3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before\ncalling device_unregister().  During device_unregister(),\ndevice_del() emits a KOBJ_REMOVE uevent and unbinds the driver while\nthe device descriptor is still expected to be valid.  As a result,\ni3c_device_uevent() and a racing modalias_show() can observe a NULL\ndesc and fall back to an uninitialized stack struct i3c_device_info,\nleaking kernel stack contents in the generated modalias.  Driver\n.remove() callbacks may also encounter an unexpected NULL desc during\nunbind.\n\nKeep desc valid until device_unregister() has completed.  Since\ndevice_unregister() drops the device reference and may free the device,\ntake an extra reference with get_device() before unregistering.  Clear\ndesc afterwards and release the extra reference with put_device().\nThis preserves the release-time invariant that desc must be NULL while\navoiding both the information leak and a potential use-after-free from\nwriting desc after the device has been released."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in i3c_master_unregister_i3c_devs(), reached only from I3C master platform/PCI driver .remove() (sysfs unbind, rmmod, or controller teardown). No network, Bluetooth, or remote packet path enters this unregister sequence.\nAC:L - Clearing desc before device_unregister() deterministically poisons KOBJ_REMOVE uevent/modalias, and the later device free races with in-flight IBI work still holding desc->dev. An attacker looping bind/unbind while sensors generate IBIs or while reading sysfs modalias controls both sides of the race.\nPR:L - Per CNA driver-removal UAF precedent (including CVE-2024-49874 on this same i3c_master_unregister path), an unprivileged local user can drive the IBI/sysfs side via world-readable I3C modalias and IIO/hwmon/MCTP clients while teardown proceeds; init-namespace root is not the minimum privilege bar.\nUI:N - No separate victim action is required; the attacker reads sysfs/uevents and/or sustains I3C IBI traffic themselves and piggybacks on driver removal without another user opening files or mounting filesystems.\nS:U - Impact is kernel heap use-after-free and stack disclosure within the host kernel. This is not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - i3c_device_uevent() and a racing modalias_show() leak uninitialized kernel stack into MODALIAS when desc is NULL. After device_unregister() drops the last reference, i3c_master_handle_ibi() can invoke the IBI handler with a freed i3c_device, a heap UAF that enables arbitrary kernel read.\nI:H - In-flight i3c_master_handle_ibi() still calls ibi->handler() on the dangling i3c_device after it is freed, and driver .remove() may skip i3c_device_disable_ibi() because desc was already cleared. Heap reuse of that object yields write and control-flow hijack primitives.\nA:H - Use-after-free of the i3c_device during unregister, and unexpected NULL desc in driver .remove() callbacks, can oops or panic the kernel even when the UAF is not fully exploited for code execution."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/i3c/master.c"],"versions":[{"version":"3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0","lessThan":"334cfb5e285cece5dc49fb3fb8ea9b70b2cb5d7e","status":"affected","versionType":"git"},{"version":"3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0","lessThan":"109995153898454c7795c2c299fd0a0b57456a4b","status":"affected","versionType":"git"},{"version":"3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0","lessThan":"c64daaaba08e490c8347ff60aacac4dd51249f91","status":"affected","versionType":"git"},{"version":"3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0","lessThan":"ef72ff6650c4ebf2b444708d84df66db42f262d9","status":"affected","versionType":"git"},{"version":"3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0","lessThan":"c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49","status":"affected","versionType":"git"},{"version":"3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0","lessThan":"94fb9786d67a8f8b899e77381620f86bad94fdf7","status":"affected","versionType":"git"},{"version":"3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0","lessThan":"4837be0f9ac2efe5e83b35a696b6242c473d280c","status":"affected","versionType":"git"},{"version":"3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0","lessThan":"d2c743efd2d1ee64e94324664808f623dd865872","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/i3c/master.c"],"versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/334cfb5e285cece5dc49fb3fb8ea9b70b2cb5d7e"},{"url":"https://git.kernel.org/stable/c/109995153898454c7795c2c299fd0a0b57456a4b"},{"url":"https://git.kernel.org/stable/c/c64daaaba08e490c8347ff60aacac4dd51249f91"},{"url":"https://git.kernel.org/stable/c/ef72ff6650c4ebf2b444708d84df66db42f262d9"},{"url":"https://git.kernel.org/stable/c/c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49"},{"url":"https://git.kernel.org/stable/c/94fb9786d67a8f8b899e77381620f86bad94fdf7"},{"url":"https://git.kernel.org/stable/c/4837be0f9ac2efe5e83b35a696b6242c473d280c"},{"url":"https://git.kernel.org/stable/c/d2c743efd2d1ee64e94324664808f623dd865872"}],"title":"i3c: master: Fix info leak and UAF in device unregister path","x_generator":{"engine":"bippy-1.2.0"}}}}