Incorrect Bitwise Shift of Integer in Linux kernel - CVE-2026-90386
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to trigger a shift-out-of-bounds condition.
The vulnerability exists due to an incorrect bitwise shift calculation in the DesignWare I3C master DAA handler when ENTDAA assigns no devices on an empty I3C bus. A local user can initiate dynamic address assignment on an empty I3C bus to trigger a shift-out-of-bounds condition.
Affected software
How to mitigate CVE-2026-90386
External References
- https://git.kernel.org/stable/c/038cf48b3170af26a70bf2dee4f8c3ac910f5176
- https://git.kernel.org/stable/c/111f559e5b6461f5f6977275716e6c5d1eb7ea27
- https://git.kernel.org/stable/c/3a1c35739efb69e8ec2a868113a0471a01bb8f29
- https://git.kernel.org/stable/c/5650b013e6bfc14c8b30be727f4a715b01860a08
- https://git.kernel.org/stable/c/618dd640ded6b94bbdb79c798a901ec564797033
- https://git.kernel.org/stable/c/63110ccc434e10d9e9d2c7d82ebfa8a6f9cedd94
- https://git.kernel.org/stable/c/754533e6169d1f10bdef7a6ba9bd7740b524e1d4
- https://git.kernel.org/stable/c/9eaac0cb4ca94e2e32c53c156ae5b813ba7ef90c