CVE-2026-80952High· 7.0▾ TwilightA flaw was found in the Linux kernel's i3c master component. During device unregistration, a race condition can occur where the device descriptor is prematurely cleared. This can lead to an information leak, exposing kernel stack contents …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 6
none → medium
— → 7.8
none → high
Last analysed / modified upstream
7.8 → 6
high → medium
7.8 → 7
A flaw was found in the Linux kernel's i3c master component. During device unregistration, a race condition can occur where the device descriptor is prematurely cleared. This can lead to an information leak, exposing kernel stack contents in the generated modalias. Additionally, this flaw could result in a potential use-after-free vulnerability, which might allow an attacker to execute arbitrary code or cause a denial of service.
kernel: i3c: master: Fix info leak and UAF in device unregister path — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.
Affected:
No fix planned:
Not affected:
Affected
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89458High· 7.0kernel: s390/dasd: Do not complete a failed ESE read as successful (CVE-2026-89458)
CVE-2026-89483Medium· 5.5kernel: nvme: zero the discard fallback page (CVE-2026-89483)
CVE-2026-89684High· 7.0kernel: nfsd: fix cpntf publish race in nfs4_init_cp_state (CVE-2026-89684)
CVE-2026-80948Medium· 5.5kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() (CVE-2026-80948)
CVE-2026-80936Medium· 5.5kernel: wifi: mt76: mt7925: cancel mlo_pm_work on stop (CVE-2026-80936)
CVE-2026-80947High· 7.0kernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (CVE-2026-80947)