CVE-2026-80678

Source
https://cve.org/CVERecord?id=CVE-2026-80678
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80678.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80678
Downstream
Published
2026-08-28T06:52:47.077Z
Modified
2026-08-29T03:47:17.086658838Z
Summary
i2c: imx: Fix slave registration race and error handling
Details

In the Linux kernel, the following vulnerability has been resolved:

i2c: imx: Fix slave registration race and error handling

In i2cimxregslave(), the slave pointer was assigned before pmruntimeresumeandget(). If pmruntimeresumeandget() failed, the error path returned without clearing i2cimx->slave, leaving it non-NULL and causing all subsequent registration attempts to fail with -EBUSY.

Additionally, because this driver uses a shared IRQ, the interrupt handler i2cimxisr() can execute concurrently and, after acquiring slavelock, dereference i2cimx->slave. The previous fix attempt added a lockless i2c_imx->slave = NULL on the error path, but that could race with the ISR under the lock and still cause a NULL pointer dereference.

Fix both issues by deferring the assignment of i2cimx->slave and i2cimx->lastslaveevent to after a successful resume, and by performing the assignment inside the slave_lock critical section. This guarantees that the slave pointer is never left stale on the error path and is always valid when observed by the interrupt handler.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80678.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f7414cd6923fd7f78e57086fc964ba2dc25db5c1
Fixed
754bc62f72fd64b202462367134ac8ce95b005de
Fixed
cfdf6e13518589f911b7eace6ccb788e4ed87397
Fixed
b9f6f4883b9ac86654e75899d0dbf8a7a96ad5d8
Fixed
d6748f6802f3eebafaa16a5e5dcfbfb9b3bc173f
Fixed
12a4f0950a158d98552cbaeacc35edccd8d975fa
Fixed
614ca6594e301ff682999797c2216e9685558a2b
Fixed
d64ec362c369bbc33833f7936d5f3a706b0d5c45

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80678.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80678.json"