Description
In the Linux kernel, the following vulnerability has been resolved:

i3c: master: Do not treat master device as a duplicate target

i3c_master_search_i3c_dev_duplicate() searches the bus for another I3C
device with the same PID as the reference device. The search can match
master->this, causing the controller itself to be returned as a
duplicate.

Since the controller is not a target device, it cannot be a duplicate of
one. Exclude master->this from matching so that the function only
returns real duplicate target devices.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel function that searches for duplicate I3C devices can match the master controller itself, mistakenly identifying it as a duplicate target. This logic flaw may cause the kernel to treat an internal controller as an external device, leading to incorrect handling, possible configuration failures or device mis‑recognition. The impact observed would be functional disruption or a denial of service to I3C bus communications, but there is no evidence of remote code execution or confidentiality compromise.

Affected Systems

The flaw affects Linux kernel and any distribution that relies on the kernel source hosting I3C master support. No specific kernel version is listed in the input; the vulnerability applies to any kernel that has not yet incorporated the upstream patch. Users should consult their vendor’s advisories for the exact version affected.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. There is no publicly documented exploitation. The likely attack vector appears to be local privileged access, requiring kernel execution or root privileges to entangle the duplicate detection routine. Overall, the risk is considered medium-low due to the low EPSS score and the absence of a known exploit.

Generated by OpenCVE AI on September 19, 2026 at 08:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the upstream patch (commit 150e71808d3715a0deefbb189c780d03fdbdc735 or later).
  • If a direct kernel upgrade is not immediately possible, apply the patched source manually by applying the relevant commit to your kernel tree and rebuilding.
  • After applying the patch or upgrade, reboot the system and verify that the I3C master no longer reports itself as a duplicate device.

Generated by OpenCVE AI on September 19, 2026 at 08:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-682

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: i3c: master: Do not treat master device as a duplicate target i3c_master_search_i3c_dev_duplicate() searches the bus for another I3C device with the same PID as the reference device. The search can match master->this, causing the controller itself to be returned as a duplicate. Since the controller is not a target device, it cannot be a duplicate of one. Exclude master->this from matching so that the function only returns real duplicate target devices.
Title i3c: master: Do not treat master device as a duplicate target
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:57:04.625Z

Reserved: 2026-09-17T16:02:15.092Z

Link: CVE-2026-93199

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:16.200

Modified: 2026-10-03T11:17:46.340

Link: CVE-2026-93199

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:17Z

Weaknesses