{"id":"CVE-2026-93200","summary":"i3c: master: Fix use-after-free of master-\u003ethis","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: Fix use-after-free of master-\u003ethis\n\nsysfs attribute callbacks for the master controller device dereference\nmaster-\u003ethis.  However, master-\u003ethis is freed in\ni3c_master_detach_free_devs() before the master device itself is\nreleased.\n\nAs a result, sysfs accesses can dereference a freed master-\u003ethis\npointer, leading to a use-after-free.\n\nKeep master-\u003ethis alive until i3c_masterdev_release(), which is called\nafter the master device and its sysfs state are being torn down. Do not\nfree master-\u003ethis as part of the normal device detach path.\n\nOn the error path in i3c_master_set_info(), reset master-\u003ethis and\nbus.cur_master to NULL before freeing the allocated device.","modified":"2026-09-18T03:46:16.099140324Z","published":"2026-09-17T16:12:21.751Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93200.json","cna_assigner":"Linux"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4f3145db05fede36b35f8249b8acde5bd5d54864"},{"type":"WEB","url":"https://git.kernel.org/stable/c/50034d8d0f797c3a7a599f750a7d3e792e80dea5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/feb0ed76601f3c2f91f08688c5a7d8b9d382f720"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93200.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93200"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0"},{"fixed":"4f3145db05fede36b35f8249b8acde5bd5d54864"},{"fixed":"50034d8d0f797c3a7a599f750a7d3e792e80dea5"},{"fixed":"feb0ed76601f3c2f91f08688c5a7d8b9d382f720"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93200.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"6.18.52"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93200.json"}}],"schema_version":"1.9.0"}