CVE-2026-72140
Description
In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() If devm_platform_get_and_ioremap_resource() returns an error, mlxbf_i2c_init_resource() frees tmp_res before reading tmp_res->io to get the error code. This results in a use-after-free. Save the error code before freeing tmp_res.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/5290a52533e09c38374963f4bb0b35121fe555c7
- https://git.kernel.org/stable/c/6a108c9f5a81bb7b29dbb1398be0089655b6bfd2
- https://git.kernel.org/stable/c/71356737a7a55c76fee847563e3d33f8e6dc6b6d
- https://git.kernel.org/stable/c/b398cbbbb9dd76210682a8c9aabd34c5168800b9
- https://git.kernel.org/stable/c/c4d9b6a0c9645366d9e4af8a6ac8347bd4c841aa
- https://git.kernel.org/stable/c/ce960a1b2caa4ad08291f28d8bcf17ad5a864e54
- https://git.kernel.org/stable/c/e6a395a71f4652261d09b572a03c96052662a056
- https://git.kernel.org/stable/c/fb267770bf822064f510c9b46743f533d8fa8a5f
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.