SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89622

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of the MCP2221 I2C/SMBus driver, where a failure to clear the `rxbuf` pointer after a transfer can lead to a use-after-free condition. This flaw may allow an attacker to exploit dangling pointers, potentially leading to arbitrary memory writes and system instability. Organizations using Linux systems with the MCP2221 driver should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-89622
Severity
HIGH
CVSS
7.8
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes mcp_i2c_smbus_read() stores the caller-supplied buffer pointer in mcp->rxbuf for the duration of a transfer but never clears it when the transfer finishes or times out. Once the caller frees or reuses the buffer, mcp->rxbuf becomes a dangling pointer. A delayed or spurious MCP2221_I2C_GET_DATA report can then drive mcp2221_raw_event() to memcpy device data into the freed memory, causing a write use-after-free. Route all return paths through a single exit point that clears mcp->rxbuf and mcp->rxbuf_size, so that the existing !mcp->rxbuf guard in the raw_event handler can reject any report arriving after the transfer has ended.