Impact
In the Linux kernel’s I3C subsystem, the function i3c_device_get_supported_xfer_mode() accesses the dev->desc pointer without first acquiring the required bus lock. Because dev->desc may be invalid or stale when the lock is not held, this unsafe dereference can trigger a kernel panic, abruptly stopping the operating system and destroying availability.
Affected Systems
All Linux kernel releases that contain the buggy i3c_device_get_supported_xfer_mode() implementation are affected. The vulnerability exists in any kernel that has not applied the patch that replaces the unsafe dereference with a reference to dev->bus, which is always valid for the lifetime of the device. Both generic kernel images and headers may be impacted, depending on the build configuration, but the flaw is present in the core kernel source tree for all supported architectures.
Risk and Exploitability
The EPSS score of 0.00154 % indicates an extremely low probability of exploitation in the wild. The CVSS score of 7.8 reflects high severity for availability. Based on the description, the likely attack vector is an attacker triggering concurrent bus activity on an I3C device without holding the bus lock, which would typically require privileged or direct physical access to the device. The vulnerability is not listed in the CISA KEV catalog, and real‑world exploitation is considered unlikely, but a successful trigger would cause a kernel panic and a denial of service.
OpenCVE Enrichment