Executive brief
A vulnerability in the Linux kernel's SMBus driver can cause a system-wide crash or 'panic.' The issue occurs when the system incorrectly attempts to reset hardware components it does not currently control, leading to a flood of error messages that overwhelm the processor. This results in a complete system freeze or 'livelock,' requiring a hard reboot and potentially disrupting business operations or services running on the affected machine.
Technical details
A vulnerability in the i2c-i801 driver's i801_access() function stems from an incorrect error handling path. When i801_check_pre() fails (e.g., returning -EBUSY), the code jumps to a cleanup label that executes iowrite8() to clear the INUSE_STS lock and status flags, even though the kernel never successfully acquired hardware ownership. This action interrupts ongoing BIOS/ACPI transactions and corrupts the SMBus hardware state machine. Subsequent calls trigger a continuous stream of 'SMBus is busy' errors; on systems with slow serial consoles, this printk flood causes a console livelock, starving processes of the mmap_lock and triggering a hung task panic. The fix involves reordering the cleanup labels to ensure hardware registers are only modified if ownership was actually obtained.
Affected products
- Linux Linux Kernel 6.3 to 6.18.38, 7.1.3
Timeline
- 2026-05-12: disclosed: Initial patch submitted by Mingyu Wang
- 2026-06-23: patched: Patch committed to stable tree
- 2026-07-20: advisory: CVE-2026-64205 published