CVE-2026-98280 PUBLISHED

drm/xe/i2c: Disable IRQ on unbind

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/i2c: Disable IRQ on unbind

Currently, struct xe_i2c is freed before SGUnit IRQ is disabled in unbind path, leaving a potential UAF in case I2C IRQ is hit during this small window. Explicitly disable I2C IRQ in xe_i2c_remove() and fix this.

(cherry picked from commit 8ba5c8b8ab3fd362267c11df2cd5a90ee46f6e24)

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 0bb78ce099265fba3808c05de1c75c649664a6cb to 571ccbc801aa4d22a22d9f924b826c77052330f0 (excl.)
  • affected from 0bb78ce099265fba3808c05de1c75c649664a6cb to f0e9f963a3d209d7dc7ddd61116118ab5da2797d (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.19 is affected
  • unaffected from 0 to 6.19 (excl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References