CVE-2019-25162: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after free. [wsa: added comment to the code, added Fixes tag]

Affected products

  • Linux Linux Kernel: from 4.3.0, before 4.14.291 (fixed in 4.14.291); from 4.15.0, before 4.19.256 (fixed in 4.19.256); from 4.20.0, before 5.4.211 (fixed in 5.4.211); from 5.5.0, before 5.10.137 (fixed in 5.10.137); from 5.11.0, before 5.15.61 (fixed in 5.15.61); from 5.16.0, before 5.18.18 (fixed in 5.18.18); …

Published 2024-02-26. Last modified 2026-08-04.