Device Reference Handling Issue in Linux Kernel i3c Protocol
CVE-2026-93283
What is CVE-2026-93283?
A vulnerability in the Linux kernel's i3c protocol can lead to improper handling during device registration processes. When the device_register() function fails within the i3c_master_register_new_i3c_devs() routine, it inadvertently triggers the release of the associated i3c_device, leading to potential memory access issues. Specifically, the device's release callback does not correctly clear pointers to device descriptors, which can leave dangling references to freed memory. This oversight can compromise system stability and security, necessitating caution during device management.
Affected Version(s)
Linux 1832ed55df45f4145335ad992fb83813cdc58b5d < 5bf498623f8397d45f85f14cd631c5e5a565c2fb
Linux d48fe8d98171e0fffdeaa8b37ce0a6444bff819b < 20a2b6df91fd782ef2ff551febef594d0b46a9a7
Linux 174ae0a3b89e7804e4ea3d31bd83d6e43f39568c