Description
In the Linux kernel, the following vulnerability has been resolved:

w1: ds28e17: reject an oversize length on an I2C block read

w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire
to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the
device. The downstream slave puts a length byte in buf[0]. The driver
then reads that many bytes into buf[1] with w1_f19_i2c_read().

buf[0] is controlled by the device and can be 0 to 255.
w1_f19_i2c_read() only rejects a zero count. The caller buffer is
I2C_SMBUS_BLOCK_MAX + 2, so 34 bytes. A length above 32 makes the read
run past it, up to about 222 bytes out of bounds.

The SMBus core does check buf[0] against I2C_SMBUS_BLOCK_MAX. That
check runs after master_xfer returns. By then the write is already
done. i2c-algo-bit rejects an oversize length before it copies, and
returns -EPROTO.

Reject a length above I2C_SMBUS_BLOCK_MAX at both RECV_LEN sites, the
same way i2c-algo-bit does.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read via an oversized I²C block read
Action: Patch Now
AI Analysis

Impact

The DS28E17 1‑Wire to I²C bridge driver allows a device to supply a length byte that represents the number of data bytes to read. The driver copies that many bytes into a 34‑byte buffer, causing a read past the end of the buffer up to about 222 bytes. This out‑of‑bounds read can expose kernel memory contents, potentially leaking sensitive information. The flaw is a classic unchecked buffer read represented by CWE-125.

Affected Systems

All Linux kernel installations that load the DS28E17 driver, with no specific kernel version range listed, as the vulnerability exists in any kernel build that includes the unpatched driver code referenced in the commit logs.

Risk and Exploitability

The CVSS v3 base score of the flaw is 7.8, indicating a high severity vulnerability. The EPSS score of less than 1% indicates a very low probability that this vulnerability will be seen in real-world exploitation at present. It is not listed in CISA’s KEV catalog. The primary vector for exploitation is physical or local access to the I²C bus, where a malicious or compromised device could issue an I²C_M_RECV_LEN transaction with an oversized length byte. Since the vulnerable code resides in kernel space and the flaw involves an unchecked buffer read, a successful exploitation could lead to information disclosure of kernel memory contents, potentially allowing privilege escalation or further attacks. The vulnerability is not remotely exploitable over a network.

Generated by OpenCVE AI on September 21, 2026 at 03:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch rejecting oversize I²C block read lengths, as applied in the referenced commit(s).
  • Verify that kernel configuration and device drivers perform a length check before invoking i2c_master_xfer, mirroring the logic used by i2c-algo-bit.
  • If an immediate kernel update is not possible, consider isolating the system’s I²C bus so that only trusted devices can communicate, thereby preventing malicious oversized length values from being transmitted.

Generated by OpenCVE AI on September 21, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the device. The downstream slave puts a length byte in buf[0]. The driver then reads that many bytes into buf[1] with w1_f19_i2c_read(). buf[0] is controlled by the device and can be 0 to 255. w1_f19_i2c_read() only rejects a zero count. The caller buffer is I2C_SMBUS_BLOCK_MAX + 2, so 34 bytes. A length above 32 makes the read run past it, up to about 222 bytes out of bounds. The SMBus core does check buf[0] against I2C_SMBUS_BLOCK_MAX. That check runs after master_xfer returns. By then the write is already done. i2c-algo-bit rejects an oversize length before it copies, and returns -EPROTO. Reject a length above I2C_SMBUS_BLOCK_MAX at both RECV_LEN sites, the same way i2c-algo-bit does.
Title w1: ds28e17: reject an oversize length on an I2C block read
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:58:57.943Z

Reserved: 2026-08-26T14:34:25.802Z

Link: CVE-2026-80931

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:18:56.893

Modified: 2026-09-14T13:18:49.327

Link: CVE-2026-80931

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:06Z

Links: CVE-2026-80931 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses