{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80953","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.804Z","datePublished":"2026-09-11T19:42:22.515Z","dateUpdated":"2026-09-13T06:28:26.721Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:28:26.721Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: adi: initialize the lock before enabling interrupts\n\nadi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR\nbefore the controller's IBI state, transfer queue list and transfer\nqueue lock are initialized.  A pending CMDR interrupt can therefore run\nadi_i3c_master_irq() and take master->xferqueue.lock before the dynamic\nlock has been initialized.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the probe ordering and the IRQ path\nadi_i3c_master_probe() -> adi_i3c_master_irq() -> xferqueue.lock, with a\npending CMDR interrupt arriving after REG_IRQ_PENDING_CMDR is unmasked.\nLockdep reported:\n\n  INFO: trying to register non-static key.\n  you didn't initialize this object before use?\n  lock_acquire+0xbb/0x290\n  _raw_spin_lock_irqsave+0x36/0x60\n  adi_i3c_master_irq+0x32/0x56 [vuln_msv]\n  adi_i3c_master_probe+0x5a/0xf47 [vuln_msv]\n\nInitialize the transfer queue and IBI state before requesting and\nunmasking the IRQ."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached from adi_i3c_master_probe() on the Analog Devices AXI/FPGA I3C platform driver, which unmasks REG_IRQ_PENDING_CMDR so adi_i3c_master_irq() runs during local boot, module load, or driver rebind; there is no network, Bluetooth, or USB packet path into this controller.\nAC:L - Unmasking CMDR with leftover pending controller state causes adi_i3c_master_irq() to run immediately and take xferqueue.lock before spin_lock_init(); stale post-reset or warm-reboot interrupt bits make this deterministic without an attacker-uncontrollable race or heap layout.\nPR:N - adi_i3c_master_probe() performs no capability or authentication checks before request_irq() and unmasking CMDR; on FPGA/SoC boards with this IP the vulnerable probe runs automatically at kernel boot without the attacker holding Linux privileges.\nUI:N - No victim action is required; a pending CMDR interrupt during driver probe at boot or reboot invokes the uninitialized-lock IRQ path without anyone opening I3C/I2C device nodes or configuring transfers.\nS:U - Impact is kernel lock and memory corruption inside the host kernel that owns the I3C master; this is not a VM escape, IOMMU bypass, or sandbox boundary crossing.\nC:H - adi_i3c_master_irq() takes the uninitialized xferqueue.lock in hard-IRQ context and may also process leftover IBI/DAA pending bits while ibi.slots is still NULL, which is undefined lock/pointer behavior that can be leveraged for kernel memory disclosure.\nI:H - Concurrent spin_lock_init() versus IRQ-context use of the same dynamic lock, plus IBI handling through a NULL slots table, can corrupt lock metadata and adjacent driver/heap state, enabling a write or control-flow primitive under conservative kernel CNA scoring.\nA:H - The commit's lockdep PoC already shows lock_acquire on a non-static key from adi_i3c_master_irq() during probe; DEBUG_SPINLOCK BUG, oops/panic, or a hung IRQ path on affected FPGA/embedded boards is full availability loss."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/i3c/master/adi-i3c-master.c"],"versions":[{"version":"a79ac2cdc91d6be3010f2e9a3b2a2ccfc26e2086","lessThan":"a15a1b95de980362c14f32f519b293b0d12ce86f","status":"affected","versionType":"git"},{"version":"a79ac2cdc91d6be3010f2e9a3b2a2ccfc26e2086","lessThan":"de8c32b0a246bbb4b44ec29e12769496a0bf66f7","status":"affected","versionType":"git"},{"version":"a79ac2cdc91d6be3010f2e9a3b2a2ccfc26e2086","lessThan":"8a53f9102a0d3eeb8784999f925028acf339c276","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/i3c/master/adi-i3c-master.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a15a1b95de980362c14f32f519b293b0d12ce86f"},{"url":"https://git.kernel.org/stable/c/de8c32b0a246bbb4b44ec29e12769496a0bf66f7"},{"url":"https://git.kernel.org/stable/c/8a53f9102a0d3eeb8784999f925028acf339c276"}],"title":"i3c: master: adi: initialize the lock before enabling interrupts","x_generator":{"engine":"bippy-1.2.0"}}}}