PT-2026-6125 · Linux+3 · Linux Kernel+3

CVE-2026-23055

·

Published

2025-12-18

·

Updated

2026-08-21

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel is susceptible to a flaw related to the handling of suspend and resume operations within the Renesas I2C driver. Specifically, inappropriate ordering of system sleep callbacks can lead to I2C transfers being attempted while the controller is suspended. This issue arises when the controller is autosuspended, preventing it from being woken up once runtime power management is disabled. During system resume, the I2C controller may not be available in time for certain devices. The root cause is that the controller is not woken up in the suspend() callback while runtime power management is still enabled. The issue manifests as a WARNING message in the system logs, indicating a transfer attempt during suspension. The affected function is i2c smbus xfer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12147
CVE-2026-23055
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20873-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-8570-1
USN-8570-2
USN-8594-1
USN-8604-1
USN-8605-1
USN-8669-1

Affected Products

Linuxmint
Linux Kernel
Renesas I2C Driver
Ubuntu