SB2026092485 - Infinite loop in Linux kernel i3c master driver



SB2026092485 - Infinite loop in Linux kernel i3c master driver

Published: September 24, 2026

Security Bulletin ID SB2026092485
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Infinite loop (CVE-ID: CVE-2026-97515)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to improper interrupt status handling in the I3C master request IBI handler when an I3C target remains stuck holding SDA low on NPCM845. An attacker with physical access can cause an I3C target to hold the SDA line low to cause a denial of service.


Remediation

Install update from vendor's website.