Impact
The vulnerability arises from the i3c driver in the Linux kernel when performing Dynamic Address Assignment (DAA). When an empty i3c bus results in no devices being assigned, the driver incorrectly calculates a mask index that becomes –1, which causes a shift operation on an unsigned value with an exponent larger than the bit width. This triggers a UBSAN “shift‑out‑of‑bounds” error that leads to undefined behavior and can collapse the kernel, effectively denying normal operation of the system. The weakness exemplifies a buffer underflow or integer underflow condition (CWE‑68, CWE‑125).
Affected Systems
The flaw is present in all Linux kernel releases that contain the affected dw‑i3c master driver before the patch referenced in kernel commit logs. It impacts any machine running those kernel versions, regardless of distribution. The issue was observed on a Gigabyte‑based AMD server running Fedora Linux kernel 7.0.11‑200.fc44.x86_64. No specific back‑port list is available in the CVE data, so all instances of the driver should be considered vulnerable until a patch is applied.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of early exploitation. However, because the flaw manifests during early boot when the kernel enumerates i3c devices, it is effectively a local, privilege‑level issue. An attacker who can influence the i3c bus—such as by connecting a malicious device—might force the driver to trigger the faulty mask calculation and cause a kernel crash, potentially leading to denial of service or privilege escalation. No evidence of a remote or unauthenticated exploitation vector exists, but patching remains a priority.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN