# CVE-2026-80952

## Summary

- **CVE ID:** CVE-2026-80952
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

i3c: master: Fix info leak and UAF in device unregister path

i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before
calling device_unregister().  During device_unregister(),
device_del() emits a KOBJ_REMOVE uevent and unbinds the driver while
the device descriptor is still expected to be valid.  As a result,
i3c_device_uevent() and a racing modalias_show() can observe a NULL
desc and fall back to an uninitialized stack struct i3c_device_info,
leaking kernel stack contents in the generated modalias.  Driver
.remove() callbacks may also encounter an unexpected NULL desc during
unbind.

Keep desc valid until device_unregister() has completed.  Since
device_unregister() drops the device reference and may free the device,
take an extra reference with get_device() before unregistering.  Clear
desc afterwards and release the extra reference with put_device().
This preserves the release-time invariant that desc must be NULL while
avoiding both the information leak and a potential use-after-free from
writing desc after the device has been released.

## Affected Products

- Linux — Linux (3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0)
- Linux — Linux (5.0)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49)
- [CNA](https://git.kernel.org/stable/c/94fb9786d67a8f8b899e77381620f86bad94fdf7)
- [CNA](https://git.kernel.org/stable/c/4837be0f9ac2efe5e83b35a696b6242c473d280c)
- [CNA](https://git.kernel.org/stable/c/d2c743efd2d1ee64e94324664808f623dd865872)
- [CNA](https://git.kernel.org/stable/c/334cfb5e285cece5dc49fb3fb8ea9b70b2cb5d7e)
- [CNA](https://git.kernel.org/stable/c/109995153898454c7795c2c299fd0a0b57456a4b)
- [CNA](https://git.kernel.org/stable/c/c64daaaba08e490c8347ff60aacac4dd51249f91)
- [CNA](https://git.kernel.org/stable/c/ef72ff6650c4ebf2b444708d84df66db42f262d9)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._