CVE-2026-93283: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_i3c_devs(), put_device() is called to drop the reference taken by device_register(). That drops the last reference, so the device's release callback i3c_device_release() runs and frees the i3c_device. Two problems follow from that: i3c_device_release() does WARN_ON(i3cdev->desc), so it warns because desc->dev->desc still points back at the descriptor. Clear it before calling put_device(). After put_device() frees the i3c_device, desc->dev is left pointing at freed memory, so clear desc->dev as well. That prevents, for example, i3c_master_unregister_i3c_devs() seeing desc->dev as non-NULL and dereferencing it.
Affected products
- Linux Linux: from 5.10.201, before 5.10.270 (fixed in 5.10.270); from 5.15.139, before 5.15.221 (fixed in 5.15.221); from 6.1.63, before 6.1.188 (fixed in 6.1.188); from 6.6.2, before 6.6.157 (fixed in 6.6.157); from 5.4.261, before 5.5 (fixed in 5.5); from 6.5.12, before 6.6 (fixed in 6.6); …
Published 2026-09-24. Last modified 2026-09-24.