{"id":"CVE-2026-80952","title":"kernel: i3c: master: Fix info leak and UAF in device unregister path (CVE-2026-80952)","summary":"A flaw was found in the Linux kernel's i3c master component. During device unregistration, a race condition can occur where the device descriptor is prematurely cleared. This can lead to an information leak, exposing kernel stack contents …","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-824","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T19:08:20+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80952.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80952.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80952"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532061"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80952"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80952"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80952.mbox"},{"url":"https://git.kernel.org/stable/c/334cfb5e285cece5dc49fb3fb8ea9b70b2cb5d7e"},{"url":"https://git.kernel.org/stable/c/109995153898454c7795c2c299fd0a0b57456a4b"},{"url":"https://git.kernel.org/stable/c/c64daaaba08e490c8347ff60aacac4dd51249f91"},{"url":"https://git.kernel.org/stable/c/ef72ff6650c4ebf2b444708d84df66db42f262d9"},{"url":"https://git.kernel.org/stable/c/c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49"},{"url":"https://git.kernel.org/stable/c/94fb9786d67a8f8b899e77381620f86bad94fdf7"},{"url":"https://git.kernel.org/stable/c/4837be0f9ac2efe5e83b35a696b6242c473d280c"},{"url":"https://git.kernel.org/stable/c/d2c743efd2d1ee64e94324664808f623dd865872"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00125,"epssPercentile":0.02578,"scores":{"vendor":7,"cna":7.8},"ingestedAt":"2026-09-14T15:23:07.455Z","slug":"CVE-2026-80952","body":"## Overview\n\nA flaw was found in the Linux kernel's i3c master component. During device unregistration, a race condition can occur where the device descriptor is prematurely cleared. This can lead to an information leak, exposing kernel stack contents in the generated modalias. Additionally, this flaw could result in a potential use-after-free vulnerability, which might allow an attacker to execute arbitrary code or cause a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80952.json)\n\n**kernel: i3c: master: Fix info leak and UAF in device unregister path** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204179,"id":"CVE-2026-80952","ts":1789490236906,"field":"cvss","old":"7.8","new":"7"},{"seq":183620,"id":"CVE-2026-80952","ts":1789356676134,"field":"cvss","old":"7.8","new":"6"},{"seq":183619,"id":"CVE-2026-80952","ts":1789356676134,"field":"severity","old":"high","new":"medium"},{"seq":153134,"id":"CVE-2026-80952","ts":1789285349176,"field":"cvss","old":null,"new":"7.8"},{"seq":153133,"id":"CVE-2026-80952","ts":1789285349176,"field":"severity","old":"none","new":"high"},{"seq":109584,"id":"CVE-2026-80952","ts":1789183732510,"field":"cvss","old":null,"new":"6"},{"seq":109583,"id":"CVE-2026-80952","ts":1789183732510,"field":"severity","old":"none","new":"medium"}]}