CVE-2026-64279
In the Linux kernel, the following vulnerability has been resolved:
i2c: core: fix adapter deregistration race
Adapters can be looked up by their id using i2c_get_adapter() which
takes a reference to the embedded struct device.
Remove the adapter from the IDR before tearing it down during
deregistration (and on registration failure) to make sure its resources
are not accessed after having been freed (e.g. the device name).
CSIRTS triage
- What
- A race condition exists in the i2c core during adapter deregistration.
- Who is affected
- Users of the i2c core.
- Urgency
- Remediation urgency is unclear due to unknown severity.
- Action
- Monitor for updates regarding this issue.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-64279
Get an email if CVE-2026-64279 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Advisory coverage (2)
- highCVE-2026-64279: In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter der…nvd · 2026-07-25
- mediumCVE-2026-64279: i2c: core: fix adapter deregistration racemsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-64279)