Description
In the Linux kernel, the following vulnerability has been resolved:

i3c: renesas: Fix out-of-bounds access for newdevs mask

When software initiates DAA (Dynamic Address Assignment), the controller
reports the result via the NRSPQP (Normal Response Queue Port Register).
The data length field of the response descriptor, which is accessible
through the NRSPQP register, indicates the number of devices remaining
after DAA. Consequently, when the bus is empty, this field contains the
maximum number of devices supported by the controller (8 for the Renesas
I3C controller).

Adjust the condition that computes the newly discovered devices bitmask
to prevent an out-of-bounds when the I3C bus is empty.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Patch Kernel
AI Analysis

Impact

The vulnerability is an out‑of‑bounds memory access in the Renesas I3C driver. When the controller performs Dynamic Address Assignment, the resulting number of devices on the bus is reported through a register field that, when the bus is empty, contains the maximum supported devices (eight). The driver’s calculation of the newly discovered devices bitmask was missing a bounds check, allowing it to read beyond the underlying array. This flaw can corrupt kernel memory and compromise system stability and integrity, as classified by CWE‑805.

Affected Systems

The flaw impacts any Linux system running a kernel prior to the commit that implements the fix. Hosts that compile or run the Renesas I3C driver and have not upgraded to a kernel containing the out‑of‑bounds check are affected. The vendor is the Linux kernel project and the product is the kernel itself; no specific kernel release numbers are given, so all affected versions are those that still contain the unpatched driver code.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1 % shows a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploitation. An attacker would need to trigger the I3C DAA routine, which typically requires local or privileged access to the hardware controller; remote exploitation is not implied by the description.

Generated by OpenCVE AI on September 15, 2026 at 19:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the Renesas I3C driver fix for out‑of‑bounds access.
  • If the system cannot be updated, disable the Renesas I3C controller or the DAA feature through kernel configuration, device‑tree changes, or by blacklisting the driver.
  • Alternatively, apply the patch from the commit referenced in the advisory to the kernel source, rebuild, and install the patched kernel.

Generated by OpenCVE AI on September 15, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-805
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Fix out-of-bounds access for newdevs mask When software initiates DAA (Dynamic Address Assignment), the controller reports the result via the NRSPQP (Normal Response Queue Port Register). The data length field of the response descriptor, which is accessible through the NRSPQP register, indicates the number of devices remaining after DAA. Consequently, when the bus is empty, this field contains the maximum number of devices supported by the controller (8 for the Renesas I3C controller). Adjust the condition that computes the newly discovered devices bitmask to prevent an out-of-bounds when the I3C bus is empty.
Title i3c: renesas: Fix out-of-bounds access for newdevs mask
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:46:39.040Z

Reserved: 2026-09-11T19:38:34.760Z

Link: CVE-2026-89728

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:03.143

Modified: 2026-09-11T20:20:03.143

Link: CVE-2026-89728

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:39Z

Links: CVE-2026-89728 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses
  • CWE-805

    Buffer Access with Incorrect Length Value