CVE-2026-80678

HIGHPre-NVD 8.48.4
EchelonGraph scoreHIGH confidence

Score 8.4 from GitHub Security Advisory (severity: HIGH) published 2026-08-28. a secondary CVSS source baseline 8.4; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, secondary
Trending — 5 sources updated this week
8.4EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 8.4Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

i2c: imx: Fix slave registration race and error handling

In i2c_imx_reg_slave(), the slave pointer was assigned before pm_runtime_resume_and_get(). If pm_runtime_resume_and_get() failed, the error path returned without clearing i2c_imx->slave, leaving it non-NULL and causing all subsequent registration attempts to fail with -EBUSY.

Additionally, because this driver uses a shared IRQ, the interrupt handler i2c_imx_isr() can execute concurrently and, after acquiring slave_lock, dereference i2c_imx->slave. The previous fix attempt added a lockless i2c_imx->slave = NULL on the error path, but that could race with the ISR under the lock and still cause a NULL pointer dereference.

Fix both issues by deferring the assignment of i2c_imx->slave and i2c_imx->last_slave_event to after a successful resume, and by performing the assignment inside the slave_lock critical section. This guarantees that the slave pointer is never left stale on the error path and is always valid when observed by the interrupt handler.

CVSS v3
8.4
EG Score
8.4(high)
EG Risk
42(Track)
EG Risk 42/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity84% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
4%
KEV
Not listed

Published

August 28, 2026

Last Modified

August 29, 2026

Advisory Details (7)

Auto-updated Aug 29, 2026
No patch confirmed yet.
generic

i2c: imx: Fix slave registration race and error handling - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/d64ec362c369bbc33833f7936d5f3a706b0d5c45
generic

i2c: imx: Fix slave registration race and error handling - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/614ca6594e301ff682999797c2216e9685558a2b
generic

i2c: imx: Fix slave registration race and error handling - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/12a4f0950a158d98552cbaeacc35edccd8d975fa
generic

i2c: imx: Fix slave registration race and error handling - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/d6748f6802f3eebafaa16a5e5dcfbfb9b3bc173f
generic

i2c: imx: Fix slave registration race and error handling - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/b9f6f4883b9ac86654e75899d0dbf8a7a96ad5d8
generic

i2c: imx: Fix slave registration race and error handling - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/cfdf6e13518589f911b7eace6ccb788e4ed87397
generic

i2c: imx: Fix slave registration race and error handling - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/754bc62f72fd64b202462367134ac8ce95b005de

Vendor Advisories for CVE-2026-80678(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Data Freshness Timeline

(refreshed 12× in last 7d / 12× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-08-30 01:22 UTCEPSS rescore
  2. 2026-08-29 20:29 UTCEG score recompute
  3. 2026-08-29 20:28 UTCGHSA enrichment
  4. 2026-08-29 07:26 UTCEG score recompute
  5. 2026-08-29 07:26 UTCGHSA enrichment
  6. 2026-08-29 06:36 UTCEG score recompute 8.40
  7. 2026-08-29 06:36 UTCGHSA enrichment
  8. 2026-08-29 06:33 UTCMITRE cvelistV5CVSS v3 → 8.4 · severity → HIGH
  9. 2026-08-28 21:42 UTCEPSS rescore
  10. 2026-08-28 08:20 UTCNVD update
  11. 2026-08-28 07:34 UTCEG score recompute
  12. 2026-08-28 07:32 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-80678?
CVE-2026-80678 is a high vulnerability published on August 28, 2026. In the Linux kernel, the following vulnerability has been resolved: i2c: imx: Fix slave registration race and error handling In i2cimxreg_slave(), the slave pointer was assigned before pmruntimeresumeandget(). If pmruntimeresumeandget() failed, the error path returned without clearing…
When was CVE-2026-80678 disclosed?
CVE-2026-80678 was first published in the National Vulnerability Database on August 28, 2026, with the most recent update on August 29, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-80678 actively exploited?
CVE-2026-80678 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 96.0% of all scored CVEs.
What is the CVSS score of CVE-2026-80678?
CVE-2026-80678 has a CVSS v3 base score of 8.4 (NVD).
How do I remediate CVE-2026-80678?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-80678, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-80678

Explore →

Is Your Infrastructure Affected by CVE-2026-80678?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.