PatchSiren cyber security CVE debrief
CVE-2026-93200 Linux CVE debrief
A use-after-free vulnerability exists in the Linux kernel's i3c master controller device. Sysfs attribute callbacks for the master controller device dereference master->this, which is freed in i3c_master_detach_free_devs() before the master device itself is released. This can lead to a use-after-free when accessing sysfs attributes. The vulnerability affects Linux kernel developers and maintainers, who should verify kernel versions and apply patches to fix the vulnerability. System administrators responsible for Linux kernel updates and security patches should review system configurations and ensure sysfs attribute callbacks are properly handled.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-10-03
Who should care
Linux kernel developers and maintainers, system administrators responsible for Linux kernel updates and security patches, and security teams should be aware of this vulnerability. They should verify Linux kernel versions and apply patches to fix the vulnerability, review system configurations, and ensure sysfs attribute callbacks are properly handled. Additionally, they should monitor system logs for potential use-after-free errors and track exceptions, re
Why it matters
A use-after-free vulnerability in the Linux kernel's i3c master controller device can lead to system crashes or potential code execution. Linux kernel developers and maintainers should verify kernel versions and apply patches to fix the vulnerability. System administrators responsible for Linux kernel updates and security patches should review system configurations and ensure sysfs attribute callbacks are properly handled.
- Verify Linux kernel versions and apply patches to fix the vulnerability
- Review system configurations and ensure sysfs attribute callbacks are properly handled
- Monitor system logs for potential use-after-free errors
Technical summary
The Linux kernel's i3c master controller device has a use-after-free vulnerability. Sysfs attribute callbacks for the master controller device dereference master->this, which is freed in i3c_master_detach_free_devs() before the master device itself is released. This can lead to a use-after-free when accessing sysfs attributes. The vulnerability affects Linux kernel developers and maintainers, who should verify kernel versions and apply patches to fix the vulnerability. System administrators responsible for Linux kernel updates and security patches should review system configurations and ensure sysfs attribute callbacks are properly handled.
Defensive priority
Verify Linux kernel versions and apply patches to fix the vulnerability.
Recommended defensive actions
- Verify Linux kernel versions and apply patches to fix the vulnerability.
- Review system configurations and ensure sysfs attribute callbacks are properly handled.
- Monitor system logs for potential use-after-free errors.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but do not specify affected or fixed versions. Linux kernel maintainers have resolved the issue. The vulnerability has been publicly disclosed and defenders should verify Linux kernel versions and apply patches to fix the vulnerability. The issue is related to the i3c master controller device and sysfs attribute callbacks. The vulnerability can lead to system crashes or potential code execution.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93200 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93200
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93200 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93200
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/23a1c4288a60e253a05a882bd8928ed61beb4a48
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4f3145db05fede36b35f8249b8acde5bd5d54864
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/50034d8d0f797c3a7a599f750a7d3e792e80dea5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/feb0ed76601f3c2f91f08688c5a7d8b9d382f720
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.