Linux Kernel Adapter Registration Vulnerability Impacting Various Systems
CVE-2026-53400
What is CVE-2026-53400?
A race condition vulnerability exists in the Linux kernel regarding adapter registration within the I2C subsystem. Specifically, the issue arises during the use of the i2c_get_adapter() function, which retrieves an I2C adapter based on its identifier. Inadequate initialization of the adapter can lead to scenarios where uninitialized data is accessed. This can cause significant operational problems, such as NULL-pointer dereferences or use-after-free situations. Proper handling of the adapter lifecycle is crucial to ensure system stability and security, particularly before registration processes such as i2c-dev chardev occur.
Affected Version(s)
Linux 6e13e641841833cc2aa5baefe89bb04bc388801b < 78793c75dc6d0ff2e4d50ad617349b328a99054e
Linux 6e13e641841833cc2aa5baefe89bb04bc388801b < 6a946038f2a5a8c29048c6af369d4e391448a5c5
Linux 6e13e641841833cc2aa5baefe89bb04bc388801b