Executive brief
The Linux kernel's Renesas I3C controller driver contains a bounds-checking flaw in its Dynamic Address Assignment (DAA) logic. When the I3C bus is empty, an incorrect calculation can cause out-of-bounds memory access, potentially leading to kernel instability or information disclosure on systems using Renesas I3C hardware controllers.
Technical details
This is a bounds-checking vulnerability in the Renesas I3C master controller driver (drivers/i3c/master/renesas-i3c.c). During DAA, the controller reports results via the NRSPQP register; when the I3C bus is empty, the data length field incorrectly indicates the maximum supported device count (8). The vulnerable code computes a bitmask using GENMASK(i3c->maxdevs - cmd->rx_count - 1, 0) without validating that cmd->rx_count is less than maxdevs, causing out-of-bounds bit operations when cmd->rx_count >= maxdevs. The fix adds a conditional check: if cmd->rx_count >= maxdevs, newdevs is set to 0; otherwise, the GENMASK is computed safely. The vulnerability is triggered locally during normal DAA operation when encountering an empty bus, requiring no special privileges or user interaction.
Affected products
- Linux Linux kernel unknown
Timeline
- 2026-07-31: patched: Fix committed upstream (commit 50dec95c)