SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64279

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's I2C subsystem, specifically during the deregistration of I2C adapters, which can lead to use-after-free conditions. This flaw can result in potential system crashes or arbitrary code execution due to improper resource management. Organizations utilizing Linux systems, particularly those relying on I2C devices, should prioritize patching to mitigate the risk associated with this high-severity vulnerability.

CVE
CVE-2026-64279
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter deregistration race Adapters can be looked up by their id using i2c_get_adapter() which takes a reference to the embedded struct device. Remove the adapter from the IDR before tearing it down during deregistration (and on registration failure) to make sure its resources are not accessed after having been freed (e.g. the device name).

Related CVEs

Other vulnerabilities affecting the same vendor(s)