Infinite loop in Linux kernel - CVE-2026-97515

 

Infinite loop in Linux kernel - CVE-2026-97515

Published: September 24, 2026


Vulnerability identifier: #VU151971
CSH Severity: Low
CVSS v4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97515
CWE-ID: CWE-835
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to cause a denial of service.

The vulnerability exists due to improper interrupt status handling in the I3C master request IBI handler when an I3C target remains stuck holding SDA low on NPCM845. An attacker with physical access can cause an I3C target to hold the SDA line low to cause a denial of service.


Affected software

Linux kernel

How to mitigate CVE-2026-97515

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins