« Volver al listado

CVE-2026-74461

Estado: RecibidaAlta (8.4)—

In the Linux kernel, the following vulnerability has been resolved:

i2c: imx: Cancel hrtimer before clearing slave pointer

In i2c_imx_unreg_slave(), the slave pointer is set to NULL after disabling interrupts. However, a pending interrupt might already have started the hrtimer (i2c_imx_slave_timeout) before the pointer was cleared. If the hrtimer fires after i2c_imx->slave is set to NULL, the timer callback i2c_imx_slave_finish_op() will call i2c_imx_slave_event() with a NULL slave pointer, which results in a use-after-free / NULL pointer dereference.

Fix by canceling the hrtimer and waiting for it to complete after disabling interrupts, before clearing the slave pointer.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local sin interacción del usuario en kernel de Linux que causa NULL pointer dereference, permitiendo DoS por crash del kernel; AV:L/PR:N/UI:N confirma acceso local sin privilegios.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74461",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.4,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "e3da77bdb4015051656bb472c295656bbea03b6f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "470fe15fb3bb2eba6629be301ca7e991ee3cfb7e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "a8a1f9ac3d763e721586f15479ef9140b216ddf3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "753060f2b77ff2f386addbd3ecadb95b9f90cddd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "affd62f5719a78135b7441aa49c8cab3c3b5e838",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "dab4762ee7f3fd0a01980d5407ba48d0261d3bff",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "6ac7702b6cc2b94aaed9ef2d95bfbefcdc90061f",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/i2c/busses/i2c-imx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/i2c/busses/i2c-imx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:17:50.763",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/470fe15fb3bb2eba6629be301ca7e991ee3cfb7e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6ac7702b6cc2b94aaed9ef2d95bfbefcdc90061f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/753060f2b77ff2f386addbd3ecadb95b9f90cddd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a8a1f9ac3d763e721586f15479ef9140b216ddf3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/affd62f5719a78135b7441aa49c8cab3c3b5e838",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dab4762ee7f3fd0a01980d5407ba48d0261d3bff",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e3da77bdb4015051656bb472c295656bbea03b6f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: Cancel hrtimer before clearing slave pointer\n\nIn i2c_imx_unreg_slave(), the slave pointer is set to NULL after\ndisabling interrupts.  However, a pending interrupt might already\nhave started the hrtimer (i2c_imx_slave_timeout) before the pointer\nwas cleared.  If the hrtimer fires after i2c_imx->slave is set to\nNULL, the timer callback i2c_imx_slave_finish_op() will call\ni2c_imx_slave_event() with a NULL slave pointer, which results in a\nuse-after-free / NULL pointer dereference.\n\nFix by canceling the hrtimer and waiting for it to complete after\ndisabling interrupts, before clearing the slave pointer."
    }
  ],
  "lastModified": "2026-08-19T17:21:03.083",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}