Out-of-bounds write in Linux kernel - CVE-2026-80951

 

Out-of-bounds write in Linux kernel - CVE-2026-80951

Published: September 13, 2026


Vulnerability identifier: #VU149449
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80951
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to write beyond the bounds of the IBI pool.

The vulnerability exists due to improper bounds checking in svc_i3c_master_handle_ibi() when processing in-band interrupt payloads from an I3C device. An attacker with physical access can send an IBI payload larger than the requested maximum payload length to write beyond the bounds of the IBI pool.


Affected software

Linux kernel

How to mitigate CVE-2026-80951

Install security update from vendor's repository.


External References

Related Security Bulletins