CVE-2026-80680

Summary

In the Linux kernel, the following vulnerability has been resolved:

i2c: amd-mp2: Unregister callback on adapter add failure

amd_mp2_register_cb() stores the platform I2C context in the MP2 PCI driver's callback table before the adapter is registered. If i2c_add_adapter() fails, probe returns and devres frees the context, but the PCI driver can still dereference the stale pointer from its IRQ and system-sleep callbacks.

Unregister the callback before returning the adapter registration error.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux529766e0a0114438887382a68d97341fbf8349fb < 9142a3dcff0d80a3a24ce159aee19ddc869d9784affected
LinuxLinux529766e0a0114438887382a68d97341fbf8349fb < 2f7789b3a9628819ebf90bcba8f9da3c139f8687affected
LinuxLinux529766e0a0114438887382a68d97341fbf8349fb < 4786d4d70dcd1e6b7e044f2348e00f201947b69caffected
LinuxLinux529766e0a0114438887382a68d97341fbf8349fb < b7c2c5c8868737926410b93d1223ada17625ead3affected
LinuxLinux529766e0a0114438887382a68d97341fbf8349fb < cf107c5983dc70fcf932a305581a5f976d908ff1affected
LinuxLinux529766e0a0114438887382a68d97341fbf8349fb < 1883a09a37fed497b9efacf736c23624a472246baffected
LinuxLinux529766e0a0114438887382a68d97341fbf8349fb < 8bf719659406e4a1b56d441e0c7da2085d891d96affected
LinuxLinux529766e0a0114438887382a68d97341fbf8349fb < 82048795242f04275a3f49ffc66ad851b6120954affected
LinuxLinux5.2affected
LinuxLinux0 < 5.2unaffected
LinuxLinux5.10.265 <= 5.10.*unaffected
LinuxLinux5.15.216 <= 5.15.*unaffected
LinuxLinux6.1.183 <= 6.1.*unaffected
LinuxLinux6.6.151 <= 6.6.*unaffected
LinuxLinux6.12.103 <= 6.12.*unaffected
LinuxLinux6.18.44 <= 6.18.*unaffected
LinuxLinux7.1.8 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References