Impact
The vulnerability is an out‑of‑bounds memory access in the Renesas I3C driver. When the controller performs Dynamic Address Assignment, the resulting number of devices on the bus is reported through a register field that, when the bus is empty, contains the maximum supported devices (eight). The driver’s calculation of the newly discovered devices bitmask was missing a bounds check, allowing it to read beyond the underlying array. This flaw can corrupt kernel memory and compromise system stability and integrity, as classified by CWE‑805.
Affected Systems
The flaw impacts any Linux system running a kernel prior to the commit that implements the fix. Hosts that compile or run the Renesas I3C driver and have not upgraded to a kernel containing the out‑of‑bounds check are affected. The vendor is the Linux kernel project and the product is the kernel itself; no specific kernel release numbers are given, so all affected versions are those that still contain the unpatched driver code.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1 % shows a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploitation. An attacker would need to trigger the I3C DAA routine, which typically requires local or privileged access to the hardware controller; remote exploitation is not implied by the description.
OpenCVE Enrichment