SB2026091315 - Out-of-bounds write in Linux kernel i3c master driver



SB2026091315 - Out-of-bounds write in Linux kernel i3c master driver

Published: September 13, 2026

Security Bulletin ID SB2026091315
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds write (CVE-ID: CVE-2026-80951)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to write beyond the bounds of the IBI pool.

The vulnerability exists due to improper bounds checking in svc_i3c_master_handle_ibi() when processing in-band interrupt payloads from an I3C device. An attacker with physical access can send an IBI payload larger than the requested maximum payload length to write beyond the bounds of the IBI pool.


Remediation

Install update from vendor's website.