Description
In the Linux kernel, the following vulnerability has been resolved:

i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()

i3c_device_get_supported_xfer_mode() uses dev->desc to obtain the
master controller. However, dev->desc must not be dereferenced unless
bus->lock is held, and this function does not take that lock.

The function only needs access to the master controller associated with
the device's bus. Use dev->bus instead, which is always valid for the
lifetime of the device and does not require dereferencing dev->desc.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel’s I3C subsystem, the function i3c_device_get_supported_xfer_mode() accesses the dev->desc pointer without first acquiring the required bus lock. Because dev->desc may be invalid or stale when the lock is not held, this unsafe dereference can trigger a kernel panic, abruptly stopping the operating system and destroying availability.

Affected Systems

All Linux kernel releases that contain the buggy i3c_device_get_supported_xfer_mode() implementation are affected. The vulnerability exists in any kernel that has not applied the patch that replaces the unsafe dereference with a reference to dev->bus, which is always valid for the lifetime of the device. Both generic kernel images and headers may be impacted, depending on the build configuration, but the flaw is present in the core kernel source tree for all supported architectures.

Risk and Exploitability

The EPSS score of 0.00154 % indicates an extremely low probability of exploitation in the wild. The CVSS score of 7.8 reflects high severity for availability. Based on the description, the likely attack vector is an attacker triggering concurrent bus activity on an I3C device without holding the bus lock, which would typically require privileged or direct physical access to the device. The vulnerability is not listed in the CISA KEV catalog, and real‑world exploitation is considered unlikely, but a successful trigger would cause a kernel panic and a denial of service.

Generated by OpenCVE AI on September 21, 2026 at 04:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that replaces the unsafe dereference of dev->desc in i3c_device_get_supported_xfer_mode() with a safe reference to dev->bus.
  • Upgrade the kernel to the latest stable release that includes the committed fix for the I3C subsystem.
  • Validate the updated kernel in a staging environment to confirm that the crash no longer occurs and that I3C operations function correctly.

Generated by OpenCVE AI on September 21, 2026 at 04:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() i3c_device_get_supported_xfer_mode() uses dev->desc to obtain the master controller. However, dev->desc must not be dereferenced unless bus->lock is held, and this function does not take that lock. The function only needs access to the master controller associated with the device's bus. Use dev->bus instead, which is always valid for the lifetime of the device and does not require dereferencing dev->desc.
Title i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:27.960Z

Reserved: 2026-08-26T14:34:25.804Z

Link: CVE-2026-80954

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:01.167

Modified: 2026-09-13T07:17:02.590

Link: CVE-2026-80954

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:23Z

Links: CVE-2026-80954 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:15:08Z

Weaknesses