CVE-2026-45863: i3c: dw: Fix memory leak in dw_i3c_master_i2c_xfers()
In the Linux kernel, the following vulnerability has been resolved:
i3c: dw: Fix memory leak in dwi3cmasteri2cxfers()
The dwi3cmasteri2cxfers() function allocates memory for the xfer structure using dwi3cmasterallocxfer(). If pmruntimeresumeandget() fails, the function returns without freeing the allocated xfer, resulting in a memory leak.
Add a dwi3cmasterfreexfer() call to the error path to ensure the allocated memory is properly freed.
Compile tested only. Issue found using a prototype static analysis tool and code review.
Affected Software
Event History
Frequently Asked Questions
What conditions are required to trigger the memory leak?
A local attacker needs low privileges and must cause dw_i3c_master_i2c_xfers() to reach the error path where pm_runtime_resume_and_get() fails after an xfer structure has been allocated. No user interaction is required.
What is the practical impact if the issue is exploited?
The vulnerability affects availability: repeated triggering of the failing path can leak allocated xfer structures and consume kernel memory. The supplied CVSS vector indicates no confidentiality or integrity impact.
How can systems be remediated?
Apply a Linux kernel update containing the fix that frees the allocated xfer structure when pm_runtime_resume_and_get() fails. The referenced stable commits provide the available upstream fix sources.