Linux Kernel Vulnerability in I2C Core Adapter Registration
CVE-2026-64589
What is CVE-2026-64589?
A vulnerability within the Linux kernel's I2C core that arises during the adapter registration process could lead to a NULL-pointer dereference if the registration fails. This issue occurs because the completion structure associated with the adapter is not initialized correctly during a failure scenario. Previously, such a failure would only result in a minor memory leak of the adapter name, but the current oversight introduces a more severe risk of system instability via a crash. Addressing this flaw is critical to maintaining robust system performance and security.
Affected Version(s)
Linux e19f31169f85c712c9fca35bfd28ceb093a9f574 < 2ce0a74bfa3acdfcdb00cf02f181f2754b451f42
Linux 3f8c4f5e9a57868fa107016c81165686d23325f2 < 3351c5e77749a0c8a1e252b95420c143ebcf07ac
Linux 3f8c4f5e9a57868fa107016c81165686d23325f2 < 034e307428119b67f5f18a35e4f4e7d15a2b9774