Executive brief
A vulnerability in the Linux kernel's I2C HID driver can cause a system lock-up or denial of service. This driver is responsible for managing input devices like touchpads or keyboards that connect via the I2C bus. An exploit could allow a local user to trigger an infinite loop in the system's interrupt handler, effectively freezing the computer and requiring a hard reboot.
Technical details
A vulnerability exists in the i2c-hid driver of the Linux kernel where the I2C_HID_READ_PENDING flag, used to serialize I2C operations, can cause a deadlock. If this flag is set during a transfer (i2c_hid_xfer) and an interrupt occurs, the interrupt handler (i2c_hid_irq) checks the flag and returns immediately without clearing the interrupt source. Because the interrupt handler is a real-time (RT) task, it re-triggers in an infinite loop, preventing the original task from clearing the flag and resulting in a CPU lock-up. The fix involves removing the redundant I2C_HID_READ_PENDING flag, as the I2C core already provides sufficient locking. Patches have been backported to multiple stable kernel branches.
Affected products
- Linux Linux Kernel 3.8 to 4.19.313, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.158, 5.16 to 6.1.90, 6.2 to 6.6.30, 6.7 to 6.8.9
Timeline
- 2024-03-18: other: Initial patch authored
- 2024-05-02: patched: Patch committed to stable trees
- 2024-05-20: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0561b65fbd53d3e788c5b0222d9112ca016fd6a1
- https://git.kernel.org/stable/c/21bfca822cfc1e71796124e93b46e0d9fa584401
- https://git.kernel.org/stable/c/29e94f295bad5be59cf4271a93e22cdcf5536722
- https://git.kernel.org/stable/c/418c5575d56410c6e186ab727bf32ae32447d497
- https://git.kernel.org/stable/c/5095b93021b899f54c9355bebf36d78854c33a22
- https://git.kernel.org/stable/c/9c0f59e47a90c54d0153f8ddc0f80d7a36207d0e
- https://git.kernel.org/stable/c/b65fb50e04a95eec34a9d1bc138454a98a5578d8