CVE-2026-93199
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-93199, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-10-03
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
i3c: master: Do not treat master device as a duplicate target
i3c_master_search_i3c_dev_duplicate() searches the bus for another I3C
device with the same PID as the reference device. The search can match
master->this, causing the controller itself to be returned as a
duplicate.
Since the controller is not a target device, it cannot be a duplicate of
one. Exclude master->this from matching so that the function only
returns real duplicate target devices.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 |
| Linux | Linux | 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 |
| Linux | Linux | 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 |
| Linux | Linux | 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 |
| Linux | Linux | 5.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |