CVE-2026-80950Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's Renesas I3C driver. This driver uses an asynchronous model for data transfers. When a transfer times out, the associated memory is freed. However, if an interrupt occurs after the memory is freed but …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 4.7
none → medium
— → 4.7
none → medium
— → 7.8
none → high
Last analysed / modified upstream
7.8 → 4.7
high → medium
7.8 → 4.7
high → medium
4.7 → 5.5
A flaw was found in the Linux kernel's Renesas I3C driver. This driver uses an asynchronous model for data transfers. When a transfer times out, the associated memory is freed. However, if an interrupt occurs after the memory is freed but before the interrupt handler is aware, it can attempt to access the freed memory, leading to a use-after-free vulnerability. This can result in a system crash, causing a Denial of Service (DoS).
kernel: i3c: renesas: Check that the transfer is valid before accessing it — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.
Not affected:
Refer to the advisory for fix availability.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80995Medium· 5.5kernel: net: mctp: hold a reference to the route device in mctp_route_lookup() (CVE-2026-80995)
CVE-2026-81006Medium· 5.5kernel: ipmi: Remove all sysfs files on registration failure (CVE-2026-81006)
CVE-2026-89452Medium· 5.5kernel: iommu/msm: Unwind probe state on registration failure (CVE-2026-89452)
CVE-2026-89486Medium· 5.5kernel: ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() (CVE-2026-89486)
CVE-2026-89522Medium· 5.5kernel: media: staging/ipu7: fix async notifier UAF on probe error path (CVE-2026-89522)
CVE-2026-89600Medium· 5.5kernel: fanotify: fix use-after-free of file range info (CVE-2026-89600)