---
id: CVE-2026-80678
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  i2c: imx: Fix slave registration race and error handling

  In i2c_imx_reg_slave(), the slave pointer was assigned before
  pm_runtime_resume_and_get()
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  i2c: imx: Fix slave registration race and error handling

  In i2c_imx_reg_slave(), the slave pointer was assigned before
  pm_runtime_resume_and_get().  If pm_runtime_resu…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
published: '2026-08-28'
updated: '2026-08-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80678'
references:
  - url: 'https://git.kernel.org/stable/c/12a4f0950a158d98552cbaeacc35edccd8d975fa'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/614ca6594e301ff682999797c2216e9685558a2b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/754bc62f72fd64b202462367134ac8ce95b005de'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b9f6f4883b9ac86654e75899d0dbf8a7a96ad5d8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cfdf6e13518589f911b7eace6ccb788e4ed87397'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d64ec362c369bbc33833f7936d5f3a706b0d5c45'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d6748f6802f3eebafaa16a5e5dcfbfb9b3bc173f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00196
epssPercentile: 0.08235
ingestedAt: '2026-08-30T04:47:10.331Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

i2c: imx: Fix slave registration race and error handling

In i2c_imx_reg_slave(), the slave pointer was assigned before
pm_runtime_resume_and_get().  If pm_runtime_resume_and_get() failed,
the error path returned without clearing i2c_imx->slave, leaving it
non-NULL and causing all subsequent registration attempts to fail
with -EBUSY.

Additionally, because this driver uses a shared IRQ, the interrupt
handler i2c_imx_isr() can execute concurrently and, after acquiring
slave_lock, dereference i2c_imx->slave.  The previous fix attempt
added a lockless i2c_imx->slave = NULL on the error path, but that
could race with the ISR under the lock and still cause a NULL pointer
dereference.

Fix both issues by deferring the assignment of i2c_imx->slave and
i2c_imx->last_slave_event to after a successful resume, and by
performing the assignment inside the slave_lock critical section.
This guarantees that the slave pointer is never left stale on the
error path and is always valid when observed by the interrupt handler.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
