From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DFC4A5678C5 for ; Fri, 11 Sep 2026 19:46:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156004; cv=none; b=mYtR1zYqeQjPHjh9wgTqa9gMgGYMU5+p7mYJhebKykFksQNbXIKTHT9lLqwu08j6jseRH0zSP9N24Ad3B8ImItOImVdn7S+JR9+jlz/ZORF3Bey78ppXsXtMLd7xM1B2diWWSE0GoC+H3BDctcSqPHdr8sF2C/RCN9sS+F4ccnE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156004; c=relaxed/simple; bh=qSH5Tvy8l1bmXexpllc5qnsg3mYp5zz6KewED3/Pis4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=R11NqES3NNqK/CJUTVtd6KPYF6cLm5K/zZr720howfjDW1Heu9LQvlGSzhS42LfYbpHHq9R1N/IJvfS9UXUcsK2auNZBZ6NasqgX2Xu8lGHhPsSjpM1nS+FbHrJ7ZwBl9L/uEoFb6+pyV/oee0IXYqMetfr5Ff0wD3u7YvG0Ugw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=gCkVO/nl; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="gCkVO/nl" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 66E721F0089A; Fri, 11 Sep 2026 19:46:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789155996; bh=cy/ig1578JLYDxwbIziIZZperRaVN4Phvaq2YiWFyCI=; h=From:To:Cc:Subject:Date:Reply-To; b=gCkVO/nli09IL7PJ1OHm84Chz4lBoFXOzR1GZbl0ujsTY9EmmRb27qi0HTr6auIwK Mol3kJSkqPDygQUqVKj1LhwvmkKDypE1RLtqPKYxVsmxfMsNhMwL5pG3ua1ldlDX77 jzWHAx0/qd0lU+Qx9W9B8bEmswAXfgmi7ebLq0Vc= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80952: i3c: master: Fix info leak and UAF in device unregister path Date: Fri, 11 Sep 2026 21:40:58 +0200 Message-ID: <2026091140-CVE-2026-80952-fb42@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3241; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=ighbqDxOC8rjLXbPVF7ZaOhFS0f/Tyj6JrEehV/NjjU=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIi2+sh5bdvJYyKnurJCqZD3DxidmxxK5Mjo5UmUSX tieWXK0I5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACZio8OwYMXVwvhdGjb8M9xT ZkxU8rtcYt2Xz7Dg5My0h0ctW0U1FO5safXm3RGyaeFMAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregister path i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before calling device_unregister(). During device_unregister(), device_del() emits a KOBJ_REMOVE uevent and unbinds the driver while the device descriptor is still expected to be valid. As a result, i3c_device_uevent() and a racing modalias_show() can observe a NULL desc and fall back to an uninitialized stack struct i3c_device_info, leaking kernel stack contents in the generated modalias. Driver .remove() callbacks may also encounter an unexpected NULL desc during unbind. Keep desc valid until device_unregister() has completed. Since device_unregister() drops the device reference and may free the device, take an extra reference with get_device() before unregistering. Clear desc afterwards and release the extra reference with put_device(). This preserves the release-time invariant that desc must be NULL while avoiding both the information leak and a potential use-after-free from writing desc after the device has been released. The Linux kernel CVE team has assigned CVE-2026-80952 to this issue. Affected and fixed versions =========================== Issue introduced in 5.0 with commit 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 and fixed in 6.12.109 with commit c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49 Issue introduced in 5.0 with commit 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 and fixed in 6.18.50 with commit 94fb9786d67a8f8b899e77381620f86bad94fdf7 Issue introduced in 5.0 with commit 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 and fixed in 7.2.4 with commit 4837be0f9ac2efe5e83b35a696b6242c473d280c Issue introduced in 5.0 with commit 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 and fixed in 7.3-rc1 with commit d2c743efd2d1ee64e94324664808f623dd865872 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80952 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/i3c/master.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49 https://git.kernel.org/stable/c/94fb9786d67a8f8b899e77381620f86bad94fdf7 https://git.kernel.org/stable/c/4837be0f9ac2efe5e83b35a696b6242c473d280c https://git.kernel.org/stable/c/d2c743efd2d1ee64e94324664808f623dd865872