{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80954","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.804Z","datePublished":"2026-09-11T19:42:23.169Z","dateUpdated":"2026-09-13T06:28:27.960Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:28:27.960Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()\n\ni3c_device_get_supported_xfer_mode() uses dev->desc to obtain the\nmaster controller.  However, dev->desc must not be dereferenced unless\nbus->lock is held, and this function does not take that lock.\n\nThe function only needs access to the master controller associated with\nthe device's bus.  Use dev->bus instead, which is always valid for the\nlifetime of the device and does not require dereferencing dev->desc."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The unlocked desc dereference is reached from local IIO sysfs reads of an I3C-backed MMC5633 magnetometer (in_magn_*_raw/in_temp_raw via iio_read_channel_info) and from /dev/iio:deviceN; I3C is an on-board host bus with no network or Bluetooth packet path.\nAC:L - A local attacker can loop those IIO reads while concurrently forcing Dynamic Address Assignment, which replaces and kfree()s i3c_dev_desc (hot-join, MIPI I3C HCI/Renesas resume re-DAA, or sysfs do_daa). The attacker drives the unlocked-read side and can retry until it races with DAA.\nPR:L - IIO channel attributes are created 0444/0644 and iio_read_channel_info performs no capability check, so an unprivileged local user on Android, automotive, or embedded I3C boards can invoke mmc5633_read_raw without init-namespace root.\nUI:N - The attacker performs their own sysfs or IIO chardev reads against an already-present I3C device; no separate victim action such as plugging hardware or mounting a filesystem is required.\nS:U - The use-after-free corrupts an i3c_dev_desc in the host kernel heap and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Unlocked load of dev->desc races with DAA's i3c_master_free_i3c_dev(), so i3c_dev_get_master() walks a freed descriptor (common.master then this->info.hdr_cap). Reclaiming that object yields a kernel read primitive; UAF is High confidentiality.\nI:H - A sprayed fake i3c_dev_desc lets the nested pointer walk interpret attacker-controlled heap as kernel objects, enabling further writes and control-flow hijack through the same freed slab; UAF is High integrity.\nA:H - Dereferencing a NULL or freed desc in i3c_dev_get_master() causes a kernel oops or panic even without a full exploit, so availability impact is High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/i3c/device.c","drivers/i3c/internals.h","drivers/i3c/master.c"],"versions":[{"version":"256a21743d911f94ce92fe28f793cd586f3860b2","lessThan":"251db58324ea4792c3f9f692ab09be148e051969","status":"affected","versionType":"git"},{"version":"256a21743d911f94ce92fe28f793cd586f3860b2","lessThan":"8bed7f4fa710914b7f05fd59998316bfb4d43385","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/i3c/device.c","drivers/i3c/internals.h","drivers/i3c/master.c"],"versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/251db58324ea4792c3f9f692ab09be148e051969"},{"url":"https://git.kernel.org/stable/c/8bed7f4fa710914b7f05fd59998316bfb4d43385"}],"title":"i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()","x_generator":{"engine":"bippy-1.2.0"}}}}