Executive brief
The i2c-imx driver in the Linux kernel contains a race condition in I2C slave device registration that can cause the registration to fail permanently and lead to system crashes. A faulty slave registration leaves internal state inconsistent, preventing any subsequent registration attempts from succeeding and potentially causing kernel null pointer exceptions when interrupt handlers execute during the race window. This affects embedded systems and devices using NXP i.MX I2C controllers in slave mode.
Technical details
The vulnerability is a race condition and error handling flaw in the i2c_imx_reg_slave() function in drivers/i2c/busses/i2c-imx.c. The slave pointer is assigned before pm_runtime_resume_and_get() is called; if the resume fails, the error path exits without clearing the slave pointer, leaving it non-NULL and causing all subsequent registration attempts to fail with -EBUSY. Additionally, the shared IRQ handler i2c_imx_isr() can execute concurrently and dereference i2c_imx->slave under slave_lock, leading to a race-to-null condition. The fix defers the slave pointer assignment to after a successful pm_runtime_resume_and_get() call and performs the assignment within the slave_lock critical section, ensuring the pointer is never stale and is always valid when accessed by the ISR. The vulnerability affects Linux kernel versions 5.11 and later; patches have been applied to stable branches.
Affected products
- Linux Linux Kernel 5.11 and later
Timeline
- 2026-08-28: disclosed
- 2026-08-09: patched