CVE-2026-93200 is a vulnerability in Linux Kernel
Published on September 17, 2026
i3c: master: Fix use-after-free of master->this
In the Linux kernel, the following vulnerability has been resolved:
i3c: master: Fix use-after-free of master->this
sysfs attribute callbacks for the master controller device dereference
master->this. However, master->this is freed in
i3c_master_detach_free_devs() before the master device itself is
released.
As a result, sysfs accesses can dereference a freed master->this
pointer, leading to a use-after-free.
Keep master->this alive until i3c_masterdev_release(), which is called
after the master device and its sysfs state are being torn down. Do not
free master->this as part of the normal device detach path.
On the error path in i3c_master_set_info(), reset master->this and
bus.cur_master to NULL before freeing the allocated device.
Products Associated with CVE-2026-93200
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 and below 4f3145db05fede36b35f8249b8acde5bd5d54864 is affected.
- Version 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 and below 50034d8d0f797c3a7a599f750a7d3e792e80dea5 is affected.
- Version 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 and below feb0ed76601f3c2f91f08688c5a7d8b9d382f720 is affected.
- Version 5.0 is affected.
- Before 5.0 is unaffected.
- Version 6.18.52, <= 6.18.* is unaffected.
- Version 7.2.6, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.