Description
In the Linux kernel, the following vulnerability has been resolved:

i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices

On an empty bus ENTDAA assigns nothing, so cmd->rx_len (the count
of addresses left unassigned) equals master->maxdevs.

The GENMASK() index master->maxdevs - cmd->rx_len - 1 then becomes -1,
which trips up UBSAN. This happens every time on boot on a Gigabyte/AMD
server:

UBSAN: shift-out-of-bounds in drivers/i3c/master/dw-i3c-master.c:905:12
shift exponent 64 is too large for 64-bit type 'long unsigned int'
CPU: 7 UID: 0 PID: 963 Comm: (udev-worker) Not tainted 7.0.11-200.fc44.x86_64 #1 PREEMPT(lazy)
Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R32_F45 04/01/2026
Call Trace:
<TASK>
dump_stack_lvl+0x5d/0x80
ubsan_epilogue+0x5/0x2b
__ubsan_handle_shift_out_of_bounds.cold+0xd7/0x1ab
dw_i3c_master_daa.cold+0x1b/0x96 [dw_i3c_master]
i3c_master_do_daa_ext.part.0+0x3e/0xf0 [i3c]

Skip the mask when no new device was assigned.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from the i3c driver in the Linux kernel when performing Dynamic Address Assignment (DAA). When an empty i3c bus results in no devices being assigned, the driver incorrectly calculates a mask index that becomes –1, which causes a shift operation on an unsigned value with an exponent larger than the bit width. This triggers a UBSAN “shift‑out‑of‑bounds” error that leads to undefined behavior and can collapse the kernel, effectively denying normal operation of the system. The weakness exemplifies a buffer underflow or integer underflow condition (CWE‑68, CWE‑125).

Affected Systems

The flaw is present in all Linux kernel releases that contain the affected dw‑i3c master driver before the patch referenced in kernel commit logs. It impacts any machine running those kernel versions, regardless of distribution. The issue was observed on a Gigabyte‑based AMD server running Fedora Linux kernel 7.0.11‑200.fc44.x86_64. No specific back‑port list is available in the CVE data, so all instances of the driver should be considered vulnerable until a patch is applied.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of early exploitation. However, because the flaw manifests during early boot when the kernel enumerates i3c devices, it is effectively a local, privilege‑level issue. An attacker who can influence the i3c bus—such as by connecting a malicious device—might force the driver to trigger the faulty mask calculation and cause a kernel crash, potentially leading to denial of service or privilege escalation. No evidence of a remote or unauthenticated exploitation vector exists, but patching remains a priority.

Generated by OpenCVE AI on September 19, 2026 at 05:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Linux kernel to the latest stable release that includes the fix for the dw‑i3c master driver.
  • If an update is unavailable, configure the kernel to bypass the DAA mask calculation by disabling or unloading the i3c_master module until a patch is released.
  • Validate that the updated driver does not trigger UBSAN on boot by reviewing /var/log/messages or dmesg output.

Generated by OpenCVE AI on September 19, 2026 at 05:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
Ubuntu USN Ubuntu USN USN-8800-1 Linux kernel (NVIDIA BaseOS) vulnerabilities
History

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-68

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices On an empty bus ENTDAA assigns nothing, so cmd->rx_len (the count of addresses left unassigned) equals master->maxdevs. The GENMASK() index master->maxdevs - cmd->rx_len - 1 then becomes -1, which trips up UBSAN. This happens every time on boot on a Gigabyte/AMD server: UBSAN: shift-out-of-bounds in drivers/i3c/master/dw-i3c-master.c:905:12 shift exponent 64 is too large for 64-bit type 'long unsigned int' CPU: 7 UID: 0 PID: 963 Comm: (udev-worker) Not tainted 7.0.11-200.fc44.x86_64 #1 PREEMPT(lazy) Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R32_F45 04/01/2026 Call Trace: <TASK> dump_stack_lvl+0x5d/0x80 ubsan_epilogue+0x5/0x2b __ubsan_handle_shift_out_of_bounds.cold+0xd7/0x1ab dw_i3c_master_daa.cold+0x1b/0x96 [dw_i3c_master] i3c_master_do_daa_ext.part.0+0x3e/0xf0 [i3c] Skip the mask when no new device was assigned.
Title i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:21.842Z

Reserved: 2026-09-11T19:38:34.809Z

Link: CVE-2026-90386

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:37.993

Modified: 2026-09-17T17:17:37.993

Link: CVE-2026-90386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T07:15:13Z

Weaknesses