Description
In the Linux kernel, the following vulnerability has been resolved:

i3c: renesas: Check that the transfer is valid before accessing it

The Renesas I3C driver uses an asynchronous model to transfer data. It
prepares a struct renesas_i3c_xfer, enqueues it, and waits for completion.
The interrupt handler dequeues the transfer, updates/uses it, and signals
the waiting thread.

If the completion times out, the waiting thread dequeues the transfer and
free it. If an interrupt fires after that, the handler may access freed
memory, leading to crashes.

Check that the transfer is still valid before accessing it in the
interrupt handler. With it clear any status flags and disable all
the interrupts to avoid triggering the same interrupts again.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free in kernel memory leading to crashes and denial of service
Action: Patch immediately
AI Analysis

Impact

The Renesas I3C driver performs asynchronous data transfers without verifying that a transfer structure remains valid when the interrupt handler processes it after a timeout. This memory, resulting in a use‑after‑free condition that can crash the kernel. The flaw is categorized as a memory corruption weakness (CWE‑825) and its primary consequence is an availability impact due to a kernel panic.

Affected Systems

The issue is present in the Linux kernel’s Renesas I3C driver for Renesas I3 i3c renesas module and has not applied the patch is potentially affected. No particular kernel version range is specified in the advisory, so all kernels that include the driver remain at risk until the fix is applied.

Risk and Exploitability

The vulnerability has a CVSS score of 7.8, indicating high severity, and an EPSS score of less than 1%, suggesting a low probability of exploitation. It is not listed in the CISA KEV catalog. Exploitation would require a timed‑ freed structure, which is non‑trivial but possible. Successful exploitation would cause a kernel crash, resulting in a denial‑of‑service impact.

Generated by OpenCVE AI on September 21, 2026 at 02:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel patch that adds validity checks before accessing the transfer structure in the interrupt handler.
  • If a kernel upgrade is not immediately feasible, disable the Renesas I3C driver by unloading the module or setting CONFIG_I3C=n in the kernel configuration.
  • Reboot the system after disabling or updating to ensure that no queued transfers remain pending.

Generated by OpenCVE AI on September 21, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid before accessing it The Renesas I3C driver uses an asynchronous model to transfer data. It prepares a struct renesas_i3c_xfer, enqueues it, and waits for completion. The interrupt handler dequeues the transfer, updates/uses it, and signals the waiting thread. If the completion times out, the waiting thread dequeues the transfer and free it. If an interrupt fires after that, the handler may access freed memory, leading to crashes. Check that the transfer is still valid before accessing it in the interrupt handler. With it clear any status flags and disable all the interrupts to avoid triggering the same interrupts again.
Title i3c: renesas: Check that the transfer is valid before accessing it
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:23.768Z

Reserved: 2026-08-26T14:34:25.804Z

Link: CVE-2026-80950

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:00.683

Modified: 2026-09-13T07:17:02.210

Link: CVE-2026-80950

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:20Z

Links: CVE-2026-80950 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference