CVE-2026-80954: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()
In the Linux kernel, the following vulnerability has been resolved:
i3c: Fix unlocked dereference of dev->desc in i3cdevicegetsupportedxfermode()
i3cdevicegetsupportedxfermode() uses dev->desc to obtain the master controller. However, dev->desc must not be dereferenced unless bus->lock is held, and this function does not take that lock.
The function only needs access to the master controller associated with the device's bus. Use dev->bus instead, which is always valid for the lifetime of the device and does not require dereferencing dev->desc.
Affected Software
Event History
Frequently Asked Questions
What systems are exposed to this issue?
Systems using the Linux kernel I3C subsystem are relevant. The issue is in i3c_device_get_supported_xfer_mode(), where the device descriptor can be dereferenced without holding the required bus lock.
What condition triggers the unsafe access?
The condition occurs when i3c_device_get_supported_xfer_mode() accesses dev->desc to locate the master controller without bus->lock being held. The descriptor is not safe to dereference under those conditions.
How is the issue addressed?
The fix obtains the master controller through dev->bus rather than dev->desc. dev->bus remains valid for the lifetime of the device and does not require dereferencing the descriptor or taking the bus lock.