Description
In the Linux kernel, the following vulnerability has been resolved:

i3c: master: adi: initialize the lock before enabling interrupts

adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR
before the controller's IBI state, transfer queue list and transfer
queue lock are initialized. A pending CMDR interrupt can therefore run
adi_i3c_master_irq() and take master->xferqueue.lock before the dynamic
lock has been initialized.

This issue was found by our static analysis tool and then manually
reviewed against the current tree.

The grounded PoC kept the probe ordering and the IRQ path
adi_i3c_master_probe() -> adi_i3c_master_irq() -> xferqueue.lock, with a
pending CMDR interrupt arriving after REG_IRQ_PENDING_CMDR is unmasked.
Lockdep reported:

INFO: trying to register non-static key.
you didn't initialize this object before use?
lock_acquire+0xbb/0x290
_raw_spin_lock_irqsave+0x36/0x60
adi_i3c_master_irq+0x32/0x56 [vuln_msv]
adi_i3c_master_probe+0x5a/0xf47 [vuln_msv]

Initialize the transfer queue and IBI state before requesting and
unmasking the IRQ.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Race Condition
Action: Update Kernel
AI Analysis

Impact

The flaw in the Linux i3c driver permits an interrupt handler to acquire a lock before the lock is properly initialized. During probe, the driver requests the IRQ and unmasks the command interrupt before setting up the transfer queue state and the dynamic lock. A pending interrupt can therefore execute the transfer‑queue lock acquisition code before the lock structure has been constructed, which can lead to undefined kernel behaviour, including spinlock corruption, deadlock, or a kernel panic. This is a classic race condition mitigated by improper initialization and is represented by CWE‑909.

Affected Systems

The vulnerability affects the Linux kernel's i3c master driver across all product is generally the standard Linux kernel distribution. No version range is listed in the input, so any kernel build prior to the patch that includes the described change may be affected.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity impact, and the EPSS score of < 1% and its absence from the KEV catalog provide additional context on the potential risk. The exploit would likely require an attacker with local or privileged access such as a malicious user who can trigger I3C commands. The vulnerability is not listed in CISA's KEV catalog.

Generated by OpenCVE AI on September 21, 2026 at 03:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that initializes the transfer queue lock before enabling interrupts
  • Rebuild the i3c driver ensuring the transfer queue lock and IBI state are fully initialized prior to enabling IRQs and consider disabling the i3c subsystem when not needed
  • If the patch is not available, disable I3C support in kernel configuration (e.g., set CONFIG_I3C=m or remove the module) to prevent the driver from loading and triggering the race

Generated by OpenCVE AI on September 21, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-909
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabling interrupts adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR before the controller's IBI state, transfer queue list and transfer queue lock are initialized. A pending CMDR interrupt can therefore run adi_i3c_master_irq() and take master->xferqueue.lock before the dynamic lock has been initialized. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the probe ordering and the IRQ path adi_i3c_master_probe() -> adi_i3c_master_irq() -> xferqueue.lock, with a pending CMDR interrupt arriving after REG_IRQ_PENDING_CMDR is unmasked. Lockdep reported: INFO: trying to register non-static key. you didn't initialize this object before use? lock_acquire+0xbb/0x290 _raw_spin_lock_irqsave+0x36/0x60 adi_i3c_master_irq+0x32/0x56 [vuln_msv] adi_i3c_master_probe+0x5a/0xf47 [vuln_msv] Initialize the transfer queue and IBI state before requesting and unmasking the IRQ.
Title i3c: master: adi: initialize the lock before enabling interrupts
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:26.721Z

Reserved: 2026-08-26T14:34:25.804Z

Link: CVE-2026-80953

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:01.040

Modified: 2026-09-13T07:17:02.463

Link: CVE-2026-80953

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:22Z

Links: CVE-2026-80953 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:45:08Z

Weaknesses
  • CWE-909

    Missing Initialization of Resource