{"id":"CVE-2026-89983","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix debugfs UAF on adapter removal\n\ni2c_del_adapter() frees the adapter's debugfs directory before it\nunregisters the adapter device, but the new_device sysf…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix debugfs UAF on adapter removal\n\ni2c_del_adapter() frees the adapter's debugfs directory before it\nunregisters the adapter device, but the new_device sysf…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 0e8926abfd7aee220e44be5566affd7a8580b50e < dc33a9762538b3250ed6b5644a4d44c748be33a6","Linux >= e2a268b0f512fb18ae5961b1fdfaf610ed6bd661 < 1f1bcd4eca6caa3e4258d9a31925112539406eb6","Linux >= 4a2be5a72865bdd219b2d8c327b9fa03e87a4a9e < f9094ace03e0a532cc6505d2e97b61ae738da4ed","Linux >= 73febd775bdbdb98c81255ff85773ac410ded5c4 < 643fb872aa04342d27dbef52b2b3cf3fe71b2c7b","Linux >= 73febd775bdbdb98c81255ff85773ac410ded5c4 < 112b3d48084c820bbccf41d9783fd122e3ac4cb0","Linux >= 73febd775bdbdb98c81255ff85773ac410ded5c4 < 552836be2d95c688eede6371f85532abe1a71232","Linux >= 73febd775bdbdb98c81255ff85773ac410ded5c4 < b15b548d52b43ba8ac4652bc2c7244a8dd1e9622","Linux >= 5.15.168 < 5.15.221","Linux >= 6.1.113 < 6.1.188","Linux >= 6.6.55 < 6.6.157","Linux 6.8"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T11:17:09.270","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89983","references":[{"url":"https://git.kernel.org/stable/c/112b3d48084c820bbccf41d9783fd122e3ac4cb0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f1bcd4eca6caa3e4258d9a31925112539406eb6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/552836be2d95c688eede6371f85532abe1a71232","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/643fb872aa04342d27dbef52b2b3cf3fe71b2c7b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b15b548d52b43ba8ac4652bc2c7244a8dd1e9622","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc33a9762538b3250ed6b5644a4d44c748be33a6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9094ace03e0a532cc6505d2e97b61ae738da4ed","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-16T10:53:53.952Z","epss":0.00206,"epssPercentile":0.1094,"slug":"CVE-2026-89983","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix debugfs UAF on adapter removal\n\ni2c_del_adapter() frees the adapter's debugfs directory before it\nunregisters the adapter device, but the new_device sysfs attribute\nstays writable until device_del(). A write racing with removal still\nreaches i2c_device_probe(), which passes the freed adap->debugfs to\ndebugfs_create_dir() as the new client's parent:\n\n  BUG: KASAN: slab-use-after-free in lookup_noperm_common+0x407/0x430\n  Read of size 4 at addr ffff88803ef87810 by task syz.0.61/6090\n   lookup_noperm_common+0x407/0x430\n   simple_start_creating+0x9c/0x110\n   debugfs_start_creating+0xdb/0x1a0\n   debugfs_create_dir+0x24/0x350\n   i2c_device_probe+0x814/0xbf0\n\nIt's technically possible to create a client after i2c_deregister_clients\nhas run. That client will never be unregistered and make\nwait_for_completion hang.\n\nClose the window by removing the new_device attribute at the start of\ni2c_del_adapter(). device_remove_file() will drain any clients left.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}