---
id: CVE-2026-89983
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  i2c: core: fix debugfs UAF on adapter removal

  i2c_del_adapter() frees the adapter's debugfs directory before it
  unregisters the adapter device, but the new_device sysf…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  i2c: core: fix debugfs UAF on adapter removal

  i2c_del_adapter() frees the adapter's debugfs directory before it
  unregisters the adapter device, but the new_device sysf…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 0e8926abfd7aee220e44be5566affd7a8580b50e <
    dc33a9762538b3250ed6b5644a4d44c748be33a6
  - >-
    Linux >= e2a268b0f512fb18ae5961b1fdfaf610ed6bd661 <
    1f1bcd4eca6caa3e4258d9a31925112539406eb6
  - >-
    Linux >= 4a2be5a72865bdd219b2d8c327b9fa03e87a4a9e <
    f9094ace03e0a532cc6505d2e97b61ae738da4ed
  - >-
    Linux >= 73febd775bdbdb98c81255ff85773ac410ded5c4 <
    643fb872aa04342d27dbef52b2b3cf3fe71b2c7b
  - >-
    Linux >= 73febd775bdbdb98c81255ff85773ac410ded5c4 <
    112b3d48084c820bbccf41d9783fd122e3ac4cb0
  - >-
    Linux >= 73febd775bdbdb98c81255ff85773ac410ded5c4 <
    552836be2d95c688eede6371f85532abe1a71232
  - >-
    Linux >= 73febd775bdbdb98c81255ff85773ac410ded5c4 <
    b15b548d52b43ba8ac4652bc2c7244a8dd1e9622
  - Linux >= 5.15.168 < 5.15.221
  - Linux >= 6.1.113 < 6.1.188
  - Linux >= 6.6.55 < 6.6.157
  - Linux 6.8
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T11:17:09.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89983'
references:
  - url: 'https://git.kernel.org/stable/c/112b3d48084c820bbccf41d9783fd122e3ac4cb0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1f1bcd4eca6caa3e4258d9a31925112539406eb6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/552836be2d95c688eede6371f85532abe1a71232'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/643fb872aa04342d27dbef52b2b3cf3fe71b2c7b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b15b548d52b43ba8ac4652bc2c7244a8dd1e9622'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dc33a9762538b3250ed6b5644a4d44c748be33a6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f9094ace03e0a532cc6505d2e97b61ae738da4ed'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T10:53:53.952Z'
epss: 0.00206
epssPercentile: 0.10945
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

i2c: core: fix debugfs UAF on adapter removal

i2c_del_adapter() frees the adapter's debugfs directory before it
unregisters the adapter device, but the new_device sysfs attribute
stays writable until device_del(). A write racing with removal still
reaches i2c_device_probe(), which passes the freed adap->debugfs to
debugfs_create_dir() as the new client's parent:

  BUG: KASAN: slab-use-after-free in lookup_noperm_common+0x407/0x430
  Read of size 4 at addr ffff88803ef87810 by task syz.0.61/6090
   lookup_noperm_common+0x407/0x430
   simple_start_creating+0x9c/0x110
   debugfs_start_creating+0xdb/0x1a0
   debugfs_create_dir+0x24/0x350
   i2c_device_probe+0x814/0xbf0

It's technically possible to create a client after i2c_deregister_clients
has run. That client will never be unregistered and make
wait_for_completion hang.

Close the window by removing the new_device attribute at the start of
i2c_del_adapter(). device_remove_file() will drain any clients left.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
