CVE-2026-80951
Received Received - Intake

Buffer Overflow in Linux Kernel I3C Master Driver

Vulnerability report for CVE-2026-80951, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: bound IBI payload to the requested max_payload_len svc_i3c_master_handle_ibi() reads the IBI payload from the RX FIFO into the IBI slot. The loop is bounded by the hardware FIFO size (SVC_I3C_FIFO_SIZE), not by the slot size. slot->data points into the IBI pool, which i3c_generic_ibi_alloc_pool() sizes at max_payload_len per slot. svc_i3c_master_request_ibi() only rejects a max_payload_len larger than SVC_I3C_FIFO_SIZE, so a driver can request a smaller one. mctp-i3c requests 1. Each readsb() then copies the controller RXCOUNT bytes (up to 31) with no check against the slot size. A device that sends more bytes than the slot holds writes past slot->data, an out-of-bounds write into the IBI pool. Bound the loop by dev->ibi->max_payload_len and clamp each read to the space left in the slot, the same way dw-i3c does. A device can still send more than the requested payload. Flush the leftover bytes from the RX FIFO so they do not leak into the next transfer.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds write issue in the Linux kernel's I3C master driver (svc). The problem occurs when handling IBI payloads. The driver reads data from hardware FIFO without checking against the allocated slot size, allowing a malicious device to write past the intended buffer and corrupt adjacent memory in the IBI pool.

Detection Guidance

This vulnerability is specific to the Linux kernel's I3C master subsystem and requires kernel-level detection. Check if your system uses the affected I3C driver (svc) by inspecting kernel logs for I3C-related errors or warnings. Commands like 'dmesg | grep -i i3c' or 'journalctl -k | grep -i i3c' may help identify issues. Ensure your kernel version is updated to a patched release.

Impact Analysis

This could allow an attacker with physical or local access to cause memory corruption, potentially leading to system crashes, privilege escalation, or arbitrary code execution. Systems using affected I3C devices with improper payload handling may be vulnerable.

Compliance Impact

This vulnerability involves an out-of-bounds write in the Linux kernel's I3C master driver, which could lead to memory corruption or arbitrary code execution. Such flaws may impact compliance with GDPR or HIPAA by compromising data integrity or security, potentially exposing sensitive information. However, specific compliance impacts depend on system configuration and deployment.

Mitigation Strategies

Update your Linux kernel to the latest stable version that includes the fix for CVE-2026-80951. If immediate patching is not possible, disable the I3C driver or restrict device access to the I3C bus until the update is applied. Monitor kernel security advisories for further guidance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80951. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart