CVE-2026-74461: Linux

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: i2c: imx: Cancel hrtimer before clearing slave pointer In i2c_imx_unreg_slave(), the slave pointer is set to NULL after disabling interrupts. However, a pending interrupt might already have started the hrtimer (i2c_imx_slave_timeout) before the pointer was cleared. If the hrtimer fires after i2c_imx->slave is set to NULL, the timer callback i2c_imx_slave_finish_op() will call i2c_imx_slave_event() with a NULL slave pointer, which results in a use-after-free / NULL pointer dereference. Fix by canceling the hrtimer and waiting for it to complete after disabling interrupts, before clearing the slave pointer.

Affected products

  • Linux Linux: from 5.11, before 5.15.216 (fixed in 5.15.216); from 5.16, before 6.1.183 (fixed in 6.1.183); from 6.2, before 6.6.151 (fixed in 6.6.151); from 6.7, before 6.12.103 (fixed in 6.12.103); from 6.13, before 6.18.44 (fixed in 6.18.44); from 6.19, before 7.1.8 (fixed in 7.1.8)

Published 2026-08-15. Last modified 2026-08-19.