{"id":"CVE-2026-98018","published":"2026-09-25T11:17:30.257","lastModified":"2026-09-25T11:17:30.257","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: i3c: serialize probe with bus removal\n\nmctp_i3c_probe() drops busdevs_lock after finding the matching bus. A\nconcurrent I3C_NOTIFY_BUS_REMOVE can then unregister and free the bus\nnetdev before probe passes its private data to mctp_i3c_add_device().\nThe latter consequently adds a list node through a freed mbus pointer.\n\nKeep busdevs_lock held until the device has been added. This also\nsatisfies the __must_hold annotation on mctp_i3c_add_device().","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/2b4707a149a55e8fa75c9ef32b359d60f470a566","tags":[]},{"url":"https://git.kernel.org/stable/c/765c5e357e67916a7aac8ead4ac2fa7d2bffe000","tags":[]},{"url":"https://git.kernel.org/stable/c/906d8dbafabfa81a30e3ade420cb9912f223a5e1","tags":[]},{"url":"https://git.kernel.org/stable/c/e6541b2747682fdb2c6ded4a7cf7c39c4067a35c","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}