Memory corruption in Linux kernel - CVE-2026-89728
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to trigger an out-of-bounds access.
The vulnerability exists due to improper bounds checking in Renesas I3C controller DAA handling when initiating dynamic address assignment on an empty I3C bus. A local user can initiate dynamic address assignment to trigger an out-of-bounds access.
When the bus is empty, the controller reports its maximum supported device count through the response descriptor data-length field.