CVE-2026-80680

NameCVE-2026-80680
DescriptionIn the Linux kernel, the following vulnerability has been resolved: i2c: amd-mp2: Unregister callback on adapter add failure amd_mp2_register_cb() stores the platform I2C context in the MP2 PCI driver's callback table before the adapter is registered. If i2c_add_adapter() fails, probe returns and devres frees the context, but the PCI driver can still dereference the stale pointer from its IRQ and system-sleep callbacks. Unregister the callback before returning the adapter registration error.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4777-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bookworm6.1.176-1vulnerable
bookworm (security)6.1.187-1fixed
trixie (security), trixie6.12.107-1fixed
forky7.1.13-1fixed
sid7.2.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcebookworm6.1.187-1DLA-4777-1
linuxsourcetrixie6.12.105-1
linuxsource(unstable)7.1.8-1

Notes

https://git.kernel.org/linus/82048795242f04275a3f49ffc66ad851b6120954 (7.2-rc6)

Search for package or bug name: Reporting problems