Junglewise Threat Intelligence

CVE-2026-80951: Linux kernel i3c master svc out-of-bounds write in IBI payload handling

CVE-2026-80951 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's i3c master Silvaco driver incorrectly bounds IBI (In-Band Interrupt) payload reads to the hardware FIFO size rather than the smaller requested buffer size, allowing a malicious or faulty I3C device to write beyond allocated memory. This can corrupt the kernel's IBI pool data structure, potentially leading to crashes or privilege escalation if exploitable.

Technical details

The vulnerability is an out-of-bounds write in svc_i3c_master_handle_ibi() in the Silvaco i3c master driver (drivers/i3c/master/svc-i3c-master.c). The IBI payload read loop bounds itself by SVC_I3C_FIFO_SIZE (up to 31 bytes) rather than dev->ibi->max_payload_len, which may be much smaller (e.g., 1 byte as requested by mctp-i3c). When a device sends more bytes than the slot->data buffer holds, readsb() copies controller RXCOUNT bytes with no bounds check, writing past the slot allocation and corrupting the IBI pool heap. The fix bounds the loop by max_payload_len, clamps each read operation to remaining slot space, and flushes excess bytes from the RX FIFO. A malicious I3C device or one with firmware defects can trigger this; no authentication or local access is required beyond physical I3C bus proximity.

Affected products

  • Linux Linux kernel versions before the fix (patch commit e2bda39d7f9f285ec803e200b5c1f17143d0b483)

Timeline

  • 2026-06-24: disclosed: Patch submitted by Maoyi Xie
  • 2026-09-14: patched: Merged into stable kernel trees via commit 35aa6730b8c5626b879a4e893fe664f59bf07d7f and related commits
  • 2026-09-11: advisory: Published as CVE-2026-80951

References

Related threats