CVE-2026-98018
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: mctp: i3c: serialize probe with bus removal
mctp_i3c_probe() drops busdevs_lock after finding the matching bus. A concurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus netdev before probe passes its private data to mctp_i3c_add_device(). The latter consequently adds a list node through a freed mbus pointer.
Keep busdevs_lock held until the device has been added. This also satisfies the __must_hold annotation on mctp_i3c_add_device().
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | c8755b29b58ec65be17bcb8c40763d2dcb1f1db5 < e6541b2747682fdb2c6ded4a7cf7c39c4067a35c | affected |
| Linux | Linux | c8755b29b58ec65be17bcb8c40763d2dcb1f1db5 < 765c5e357e67916a7aac8ead4ac2fa7d2bffe000 | affected |
| Linux | Linux | c8755b29b58ec65be17bcb8c40763d2dcb1f1db5 < 906d8dbafabfa81a30e3ade420cb9912f223a5e1 | affected |
| Linux | Linux | c8755b29b58ec65be17bcb8c40763d2dcb1f1db5 < 2b4707a149a55e8fa75c9ef32b359d60f470a566 | affected |
| Linux | Linux | 6.7 | affected |
| Linux | Linux | 0 < 6.7 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/e6541b2747682fdb2c6ded4a7cf7c39c4067a35c
- https://git.kernel.org/stable/c/765c5e357e67916a7aac8ead4ac2fa7d2bffe000
- https://git.kernel.org/stable/c/906d8dbafabfa81a30e3ade420cb9912f223a5e1
- https://git.kernel.org/stable/c/2b4707a149a55e8fa75c9ef32b359d60f470a566
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.