Impact
The Linux kernel function that searches for duplicate I3C devices can match the master controller itself, mistakenly identifying it as a duplicate target. This logic flaw may cause the kernel to treat an internal controller as an external device, leading to incorrect handling, possible configuration failures or device mis‑recognition. The impact observed would be functional disruption or a denial of service to I3C bus communications, but there is no evidence of remote code execution or confidentiality compromise.
Affected Systems
The flaw affects Linux kernel and any distribution that relies on the kernel source hosting I3C master support. No specific kernel version is listed in the input; the vulnerability applies to any kernel that has not yet incorporated the upstream patch. Users should consult their vendor’s advisories for the exact version affected.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. There is no publicly documented exploitation. The likely attack vector appears to be local privileged access, requiring kernel execution or root privileges to entangle the duplicate detection routine. Overall, the risk is considered medium-low due to the low EPSS score and the absence of a known exploit.
OpenCVE Enrichment