Description
In the Linux kernel, the following vulnerability has been resolved:

i3c: master: svc: bound IBI payload to the requested max_payload_len

svc_i3c_master_handle_ibi() reads the IBI payload from the RX FIFO into
the IBI slot. The loop is bounded by the hardware FIFO size
(SVC_I3C_FIFO_SIZE), not by the slot size.

slot->data points into the IBI pool, which i3c_generic_ibi_alloc_pool()
sizes at max_payload_len per slot. svc_i3c_master_request_ibi() only
rejects a max_payload_len larger than SVC_I3C_FIFO_SIZE, so a driver can
request a smaller one. mctp-i3c requests 1. Each readsb() then copies the
controller RXCOUNT bytes (up to 31) with no check against the slot size.
A device that sends more bytes than the slot holds writes past
slot->data, an out-of-bounds write into the IBI pool.

Bound the loop by dev->ibi->max_payload_len and clamp each read to the
space left in the slot, the same way dw-i3c does. A device can still send
more than the requested payload. Flush the leftover bytes from the RX FIFO
so they do not leak into the next transfer.
Published: 2026-09-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption with potential for arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel i3c master driver performs an out‑of‑bounds write when an interrupt‑bus‑indication (IBI) payload larger than the allocated slot size is received. The read loop is bounded only by the hardware FIFO size, not by the slot buffer length, so device data is copied directly into kernel memory without a bounds check. If an attacker can influence the payload size, the resulting memory corruption can compromise kernel integrity and potentially allow an attacker to execute code with elevated privileges. The description indicates that the vulnerability is an out‑of‑bounds write (CWE‑787).

Affected Systems

All Linux kernel builds that compile the i3c master driver are impacted. Versions that do not include the patch fixing the unbounded copy loop are vulnerable. This applies to any system where the generic i3c master module is loaded, whether built‑in or as a module, across all hardware platforms that provide an I3C bus.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low probability of real‑world exploitation, and the vulnerability is not yet listed in the CISA KEV catalog, implying no publicly documented exploits. However, exploitation requires a device that can transmit a larger IBI payload, so the likely attack vector is a malicious or compromised I3C device physically attached to the target system—this is inferred from the nature of the vulnerability. In environments where physical access to the I3C bus is possible, the risk can be moderate; otherwise the risk remains low. The CVSS_base score of 6.1 reflects the severity of the out‑of‑bounds write and its potential to lead to code execution.

Generated by OpenCVE AI on September 21, 2026 at 04:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that includes the patch fixing the out‑of‑bounds write in the i3c master driver.
  • If a kernel upgrade cannot be performed immediately, reconfigure the kernel to disable or blacklist the i3c master driver so that it is not loaded at boot or in runtime.
  • Implement device authorization on the I3C bus, such as removing or isolating untrusted devices, to prevent the transmission of oversized IBI payloads.

Generated by OpenCVE AI on September 21, 2026 at 04:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: bound IBI payload to the requested max_payload_len svc_i3c_master_handle_ibi() reads the IBI payload from the RX FIFO into the IBI slot. The loop is bounded by the hardware FIFO size (SVC_I3C_FIFO_SIZE), not by the slot size. slot->data points into the IBI pool, which i3c_generic_ibi_alloc_pool() sizes at max_payload_len per slot. svc_i3c_master_request_ibi() only rejects a max_payload_len larger than SVC_I3C_FIFO_SIZE, so a driver can request a smaller one. mctp-i3c requests 1. Each readsb() then copies the controller RXCOUNT bytes (up to 31) with no check against the slot size. A device that sends more bytes than the slot holds writes past slot->data, an out-of-bounds write into the IBI pool. Bound the loop by dev->ibi->max_payload_len and clamp each read to the space left in the slot, the same way dw-i3c does. A device can still send more than the requested payload. Flush the leftover bytes from the RX FIFO so they do not leak into the next transfer.
Title i3c: master: svc: bound IBI payload to the requested max_payload_len
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:07.543Z

Reserved: 2026-08-26T14:34:25.804Z

Link: CVE-2026-80951

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:00.803

Modified: 2026-09-14T13:18:50.580

Link: CVE-2026-80951

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:21Z

Links: CVE-2026-80951 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:15:08Z

Weaknesses