SB2026091315 - Out-of-bounds write in Linux kernel i3c master driver
Published: September 13, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-80951)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to write beyond the bounds of the IBI pool.
The vulnerability exists due to improper bounds checking in svc_i3c_master_handle_ibi() when processing in-band interrupt payloads from an I3C device. An attacker with physical access can send an IBI payload larger than the requested maximum payload length to write beyond the bounds of the IBI pool.
Remediation
Install update from vendor's website.