Executive brief
The Linux kernel's Mellanox BlueField I2C driver contains a use-after-free vulnerability in resource initialization. When an error occurs during resource mapping, the driver frees memory but then attempts to read the freed memory to retrieve the error code, potentially causing system instability or denial of service. This affects systems using Mellanox BlueField network interface cards with I2C controllers.
Technical details
The vulnerability is a use-after-free in the mlxbf_i2c_init_resource() function in drivers/i2c/busses/i2c-mlxbf.c. When devm_platform_get_and_ioremap_resource() or devm_ioremap_resource() returns an error, the code frees the temporary resource structure (tmp_res) via devm_kfree() and then attempts to read tmp_res->io to extract the error code via PTR_ERR(). The fix is simple: save the error code to a local variable before freeing the memory, then return the saved error value. The vulnerability affects Linux kernel versions v5.10 and later. No user interaction or network access is required; a local attacker with the ability to load kernel modules or trigger device probe operations could potentially exploit this.
Affected products
- Linux Linux kernel v5.10 and later
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched