CVE-2026-98280: drm/xe/i2c: Disable IRQ on unbind
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/i2c: Disable IRQ on unbind
Currently, struct xei2c is freed before SGUnit IRQ is disabled in unbind path, leaving a potential UAF in case I2C IRQ is hit during this small window. Explicitly disable I2C IRQ in xei2cremove() and fix this.
(cherry picked from commit 8ba5c8b8ab3fd362267c11df2cd5a90ee46f6e24)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Explicitly disable the I2C IRQ in xe_i2c_remove() before freeing struct xe_i2c during unbind.
xe_i2c I2C IRQ = disabled