Executive brief
A vulnerability was identified in the Linux kernel's I2C driver for Realtek RTL9300 chips, which are commonly used in networking hardware. A local user could provide a specially crafted input that causes the system to access memory outside of intended boundaries. This could lead to a system crash, data exposure, or potentially allow an attacker to gain elevated control over the device.
Technical details
An out-of-bounds (OOB) read/write vulnerability exists in the rtl9300_i2c_smbus_xfer function within drivers/i2c/busses/i2c-rtl9300.c. The root cause is a failure to validate the 'data->block[0]' variable, which is provided by the user, before using it to configure I2C transfers. An attacker with local access can provide a value exceeding I2C_SMBUS_BLOCK_MAX, leading to memory corruption or information disclosure. The issue has been resolved by adding a check to ensure the block length is between 1 and I2C_SMBUS_BLOCK_MAX. The fix is available in kernel versions 6.16.4 and later.
Affected products
- Linux Linux Kernel 6.13 to 6.16.3
Timeline
- 2025-08-10: patched: Initial patch authored by Alex Guo
- 2025-09-05: disclosed: CVE-2025-39680 published