Out-of-bounds write in Linux kernel - CVE-2026-80951
Published: September 13, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to write beyond the bounds of the IBI pool.
The vulnerability exists due to improper bounds checking in svc_i3c_master_handle_ibi() when processing in-band interrupt payloads from an I3C device. An attacker with physical access can send an IBI payload larger than the requested maximum payload length to write beyond the bounds of the IBI pool.