← All Advisories

CVE-2026-89622

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89622

Key Details

CVECVE-2026-89622
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-21
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes

mcp_i2c_smbus_read() stores the caller-supplied buffer pointer in

mcp->rxbuf for the duration of a transfer but never clears it when the

transfer finishes or times out. Once the caller frees or reuses the

buffer, mcp->rxbuf becomes a dangling pointer. A delayed or spurious

MCP2221_I2C_GET_DATA report can then drive mcp2221_raw_event() to

memcpy device data into the freed memory, causing a write

use-after-free.

Route all return paths through a single exit point that clears

mcp->rxbuf and mcp->rxbuf_size, so that the existing !mcp->rxbuf guard

in the raw_event handler can reject any report arriving after the

transfer has ended. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89622
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89622