Executive brief
The Renesas I3C controller driver in the Linux kernel has a race condition where an interrupt handler may access freed memory. If a data transfer operation times out, the main thread frees the transfer structure; if an interrupt fires after that point, the handler crashes trying to access the freed memory. This can cause system crashes or undefined behavior on systems using Renesas I3C controllers.
Technical details
A use-after-free vulnerability exists in the Renesas I3C master controller driver (drivers/i3c/master/renesas-i3c.c). The driver uses an asynchronous transfer model where a transfer structure is enqueued and the waiting thread times out, dequeues, and frees the transfer. However, if the interrupt handler fires after the structure is freed, it attempts to dereference the freed pointer, causing a crash. The fix adds null-pointer checks in the interrupt handlers (renesas_i3c_tx_isr, renesas_i3c_resp_isr, renesas_i3c_tend_isr, renesas_i3c_rx_isr) to verify the transfer is still valid before accessing it. When a null transfer is detected, the handler masks all interrupts and clears status flags to prevent further interrupt triggers. No authentication or special privileges are required to trigger this condition; any user with access to trigger I3C transfers on an affected Renesas controller can potentially cause a kernel panic.
Affected products
- Linux Linux kernel through 6.9.y (fixed in multiple stable branches)
Timeline
- 2026-09-11: disclosed
- 2026-07-13: patched: Fix committed upstream; backported to stable kernels