Impact
The Linux kernel i3c master driver performs an out‑of‑bounds write when an interrupt‑bus‑indication (IBI) payload larger than the allocated slot size is received. The read loop is bounded only by the hardware FIFO size, not by the slot buffer length, so device data is copied directly into kernel memory without a bounds check. If an attacker can influence the payload size, the resulting memory corruption can compromise kernel integrity and potentially allow an attacker to execute code with elevated privileges. The description indicates that the vulnerability is an out‑of‑bounds write (CWE‑787).
Affected Systems
All Linux kernel builds that compile the i3c master driver are impacted. Versions that do not include the patch fixing the unbounded copy loop are vulnerable. This applies to any system where the generic i3c master module is loaded, whether built‑in or as a module, across all hardware platforms that provide an I3C bus.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of real‑world exploitation, and the vulnerability is not yet listed in the CISA KEV catalog, implying no publicly documented exploits. However, exploitation requires a device that can transmit a larger IBI payload, so the likely attack vector is a malicious or compromised I3C device physically attached to the target system—this is inferred from the nature of the vulnerability. In environments where physical access to the I3C bus is possible, the risk can be moderate; otherwise the risk remains low. The CVSS_base score of 6.1 reflects the severity of the out‑of‑bounds write and its potential to lead to code execution.
OpenCVE Enrichment
Debian DSA