CVE-2026-98218: i2c: atr: fix dangling adapter pointer on add failure
Published Oct 6, 2026
·Updated
i2c: atr: fix dangling adapter pointer on add failure
Affected Software
1 affected component
Linux Linux kernel
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In i2c_atr_add_adapter(), clear atr->adapter[chan_id] on the i2c_add_adapter() error path before freeing chan, and prevent slot reuse by returning -EEXIST when the slot is already occupied.
Event History
Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:34 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are exposed to this issue?
The issue is relevant to Linux kernel systems that use the I2C ATR code path and encounter a failure while adding an adapter with i2c_add_adapter(). The provided information does not establish that all default Linux kernel configurations use this path.
2
What happens after an adapter-add failure?
The channel slot can retain a pointer to freed memory. Later adapter deletion or cleanup can use that dangling pointer, and attempts to reuse the channel can fail with -EEXIST.