CVE-2026-64279

Linux kernel (GCP) vulnerabilities

Beschreibung

Im Linux-Kernel wurde die folgende Schwachstelle behoben: i2c: core: Behebung des Rennzustands bei der Adapterde-Registrierung Adapter können über ihre ID mit i2c_get_adapter() abgefragt werden, was einen Verweis auf das eingebettete struct device nimmt. Entfernen Sie den Adapter aus dem IDR, bevor er während der De-Registrierung (und bei Registrierungsfehlern) abgebaut wird, um sicherzustellen, dass seine Ressourcen nicht nach ihrer Freigabe zugegriffen werden (z. B. der Gerätenamen).

Metriken

Severity
medium
kein öffentlicher PoC bekannt
4.7
Quelle: nvd-v3
3.0 %
Niedrig — CVE gehört zu den unteren 10 % der heute bewerteten CVEs.
0.1 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-07 09:05 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-08 09:18 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Reference: https://git.kernel.org/stable/c/11dfa37bf544cc806f21742ca2fd2d841bd7032e
    • Reference: https://git.kernel.org/stable/c/35dbd1f1f603401155cbd3a180bb18e3a3b675b8
    • Reference: https://git.kernel.org/stable/c/9882a9bd74db08e7bae5821a7050627ae92d3380
    • Reference: https://git.kernel.org/stable/c/b1a58ed9eab146b36f41a55db8f5d7ce9fdedf3f
  2. CVE Modified2026-09-08 09:18 UTC· 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/64xxx/CVE-2026-64279.json">CVE-2026-64279</a>
    • Reference: https://cert-portal.siemens.com/productcert/html/ssa-019113.html
  3. CVE Modified2026-08-17 05:17 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Affected: Linux, LinuxLinux, Linux
  4. New CVE Received2026-07-25 10:17 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
    • Affected: Linux, Linux
    • Description: In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter deregistration race Adapters can be looked up by their id using i2c_get_adapter() which takes a reference to the embedded struct device. Remove the adapter from the IDR before tearing it down during deregistration (and on registration failure) to make sure its resources are not accessed after having been freed (e.g. the device name).
    • Reference: https://git.kernel.org/stable/c/11dfa37bf544cc806f21742ca2fd2d841bd7032e
    • Reference: https://git.kernel.org/stable/c/35dbd1f1f603401155cbd3a180bb18e3a3b675b8

Betroffene Betriebssysteme

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / linux-aws-6.8jammy

  • linux

    ubuntu / linux-azureresolute

  • linux

    ubuntu / linux-azuretrusty

  • linux

    ubuntu / linux-azurexenial

  • linux

    ubuntu / linux-azure-4.15bionic

  • linux

    ubuntu / linux-azure-5.4bionic

  • linux

    ubuntu / linux-azure-fdenoble

  • linux

    ubuntu / linux-azure-fderesolute

  • linux

    ubuntu / linux-azure-fde-6.8jammy

  • linux

    ubuntu / linux-azure-fipsbionic

  • linux

    ubuntu / linux-azure-fipsfocal

  • linux

    ubuntu / linux-azure-fipsnoble

  • linux

    ubuntu / linux-fipsjammy

  • linux

    ubuntu / linux-gcp-7.0noble

  • linux

    ubuntu / linux-gkejammy

  • linux

    ubuntu / linux-nvidia-tegranoble

  • linux

    ubuntu / linux-raspinoble

  • linux

    ubuntu / linux-raspi-realtimenoble

  • linux

    linux / linux_kernel2.6.12

  • linux

    linux / linux_kernel2.6.15

Quellen & Referenzen

Verknüpfte CVEs

1392 weitere CVEs anzeigen
IDCVE-2026-64279
Linux kernel (GCP) vulnerabilities — CVE-2026-64279 | NEOSEC Intel