« Volver al listado

CVE-2026-80678

Estado: RecibidaAlta (8.4)—

In the Linux kernel, the following vulnerability has been resolved:

i2c: imx: Fix slave registration race and error handling

In i2c_imx_reg_slave(), the slave pointer was assigned before pm_runtime_resume_and_get(). If pm_runtime_resume_and_get() failed, the error path returned without clearing i2c_imx->slave, leaving it non-NULL and causing all subsequent registration attempts to fail with -EBUSY.

Additionally, because this driver uses a shared IRQ, the interrupt handler i2c_imx_isr() can execute concurrently and, after acquiring slave_lock, dereference i2c_imx->slave. The previous fix attempt added a lockless i2c_imx->slave = NULL on the error path, but that could race with the ISR under the lock and still cause a NULL pointer dereference.

Leer descripción completaMostrar menos

Fix both issues by deferring the assignment of i2c_imx->slave and i2c_imx->last_slave_event to after a successful resume, and by performing the assignment inside the slave_lock critical section. This guarantees that the slave pointer is never left stale on the error path and is always valid when observed by the interrupt handler.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local en kernel Linux sin interacción: acceso local (AV:L, PR:N, UI:N) permite escalada de privilegios mediante race condition. Impactos: DoS por NULL pointer dereference y reinicio del sistema.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80678",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.4,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "754bc62f72fd64b202462367134ac8ce95b005de",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "cfdf6e13518589f911b7eace6ccb788e4ed87397",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "b9f6f4883b9ac86654e75899d0dbf8a7a96ad5d8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "d6748f6802f3eebafaa16a5e5dcfbfb9b3bc173f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "12a4f0950a158d98552cbaeacc35edccd8d975fa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "614ca6594e301ff682999797c2216e9685558a2b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f7414cd6923fd7f78e57086fc964ba2dc25db5c1",
              "lessThan": "d64ec362c369bbc33833f7936d5f3a706b0d5c45",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/i2c/busses/i2c-imx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.217",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/i2c/busses/i2c-imx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-28T08:16:53.107",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/12a4f0950a158d98552cbaeacc35edccd8d975fa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/614ca6594e301ff682999797c2216e9685558a2b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/754bc62f72fd64b202462367134ac8ce95b005de",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b9f6f4883b9ac86654e75899d0dbf8a7a96ad5d8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cfdf6e13518589f911b7eace6ccb788e4ed87397",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d64ec362c369bbc33833f7936d5f3a706b0d5c45",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d6748f6802f3eebafaa16a5e5dcfbfb9b3bc173f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: Fix slave registration race and error handling\n\nIn i2c_imx_reg_slave(), the slave pointer was assigned before\npm_runtime_resume_and_get().  If pm_runtime_resume_and_get() failed,\nthe error path returned without clearing i2c_imx->slave, leaving it\nnon-NULL and causing all subsequent registration attempts to fail\nwith -EBUSY.\n\nAdditionally, because this driver uses a shared IRQ, the interrupt\nhandler i2c_imx_isr() can execute concurrently and, after acquiring\nslave_lock, dereference i2c_imx->slave.  The previous fix attempt\nadded a lockless i2c_imx->slave = NULL on the error path, but that\ncould race with the ISR under the lock and still cause a NULL pointer\ndereference.\n\nFix both issues by deferring the assignment of i2c_imx->slave and\ni2c_imx->last_slave_event to after a successful resume, and by\nperforming the assignment inside the slave_lock critical section.\nThis guarantees that the slave pointer is never left stale on the\nerror path and is always valid when observed by the interrupt handler."
    }
  ],
  "lastModified": "2026-08-29T07:16:50.230",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}