🟡 Medium  |  Source: Microsoft Security Response Center


CVE-2026-64205 is a kernel-level vulnerability in the i2c-i801 driver, which handles communication between a processor and low-level hardware components such as temperature sensors and power management chips. The flaw involves corruption of the hardware state machine during error handling, which could lead to unpredictable behaviour or system instability. While rooted in Linux kernel internals, this is relevant to Azure environments where the underlying host infrastructure or Linux-based virtual machines may be affected.

Security Architect’s Take: Review whether your Azure Linux VM workloads or custom images include the affected i2c-i801 kernel module and apply available kernel patches promptly. If running sensitive workloads on Linux VMs, consider prioritising patching cycles and monitoring Microsoft’s update guidance for confirmation of affected Azure services or host infrastructure.

Original advisory: CVE-2026-64205 i2c: i801: fix hardware state machine corruption in error path