---
id: CVE-2019-25162
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  i2c: Fix a potential use after free

  Free the adap structure only after we are done using it.
  This patch just moves the put_device() down a bit to avoid the
  use after f…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  i2c: Fix a potential use after free

  Free the adap structure only after we are done using it.
  This patch just moves the put_device() down a bit to avoid the
  use after f…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.3.0, < 4.14.291'
  - 'linux_kernel >= 4.15.0, < 4.19.256'
  - 'linux_kernel >= 4.20.0, < 5.4.211'
  - 'linux_kernel >= 5.5.0, < 5.10.137'
  - 'linux_kernel >= 5.11.0, < 5.15.61'
  - 'linux_kernel >= 5.16.0, < 5.18.18'
  - 'linux_kernel >= 5.19.0, < 5.19.2'
patched:
  - linux_kernel 5.19.2
published: '2024-02-26'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25162'
references:
  - url: 'https://git.kernel.org/stable/c/12b0606000d0828630c033bf0c74c748464fe87d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/23a191b132cd87f746c62f3dc27da33683d85829'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/35927d7509ab9bf41896b7e44f639504eae08af7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/81cb31756888bb062e92d2dca21cd629d77a46a9'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/871a1e94929a27bf6e2cd99523865c840bbc2d87'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e4c72c06c367758a14f227c847f9d623f1994ecf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e6412ba3b6508bdf9c074d310bf4144afa6aec1a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e8e1a046cf87c8b1363e5de835114f2779e2aaf4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/12b0606000d0828630c033bf0c74c748464fe87d'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/23a191b132cd87f746c62f3dc27da33683d85829'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/35927d7509ab9bf41896b7e44f639504eae08af7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/81cb31756888bb062e92d2dca21cd629d77a46a9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/871a1e94929a27bf6e2cd99523865c840bbc2d87'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e4c72c06c367758a14f227c847f9d623f1994ecf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e6412ba3b6508bdf9c074d310bf4144afa6aec1a'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e8e1a046cf87c8b1363e5de835114f2779e2aaf4'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.00378
epssPercentile: 0.28925
ingestedAt: '2026-08-04T10:39:38.076Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/uthrasri/CVE-2019-25162'
  checkedAt: '2026-09-25T08:20:42.375Z'
exploitAvailable: true
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

i2c: Fix a potential use after free

Free the adap structure only after we are done using it.
This patch just moves the put_device() down a bit to avoid the
use after free.

[wsa: added comment to the code, added Fixes tag]

## Affected

- `linux_kernel >= 4.3.0, < 4.14.291`
- `linux_kernel >= 4.15.0, < 4.19.256`
- `linux_kernel >= 4.20.0, < 5.4.211`
- `linux_kernel >= 5.5.0, < 5.10.137`
- `linux_kernel >= 5.11.0, < 5.15.61`
- `linux_kernel >= 5.16.0, < 5.18.18`
- `linux_kernel >= 5.19.0, < 5.19.2`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.19.2`
