Junglewise Threat Intelligence

CVE-2026-89728: Linux kernel i3c Renesas driver out-of-bounds access

CVE-2026-89728 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Renesas I3C controller driver contains a bounds-checking flaw in its Dynamic Address Assignment (DAA) logic. When the I3C bus is empty, an incorrect calculation can cause out-of-bounds memory access, potentially leading to kernel instability or information disclosure on systems using Renesas I3C hardware controllers.

Technical details

This is a bounds-checking vulnerability in the Renesas I3C master controller driver (drivers/i3c/master/renesas-i3c.c). During DAA, the controller reports results via the NRSPQP register; when the I3C bus is empty, the data length field incorrectly indicates the maximum supported device count (8). The vulnerable code computes a bitmask using GENMASK(i3c->maxdevs - cmd->rx_count - 1, 0) without validating that cmd->rx_count is less than maxdevs, causing out-of-bounds bit operations when cmd->rx_count >= maxdevs. The fix adds a conditional check: if cmd->rx_count >= maxdevs, newdevs is set to 0; otherwise, the GENMASK is computed safely. The vulnerability is triggered locally during normal DAA operation when encountering an empty bus, requiring no special privileges or user interaction.

Affected products

  • Linux Linux kernel unknown

Timeline

  • 2026-07-31: patched: Fix committed upstream (commit 50dec95c)

References

Related threats