Back

HIGH

i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue

Published May 8, 2026

Description

The logic used to abort the DMA ring contains several flaws:

1. The driver unconditionally issues a ring abort even when the ring has already stopped. 2. The completion used to wait for abort completion is never re-initialized, resulting in incorrect wait behavior. 3. The abort sequence unintentionally clears RING_CTRL_ENABLE, which resets hardware ring pointers and disrupts the controller state. 4. If the ring is already stopped, the abort operation should be considered successful without attempting further action.

Fix the abort handling by checking whether the ring is running before issuing an abort, re-initializing the completion when needed, ensuring that RING_CTRL_ENABLE remains asserted during abort, and treating an already stopped ring as a successful condition.

Affected products

Remediation

Red Hat statement

Red Hat acknowledges the upstream Linux kernel correction for «i3c» as described in COMMENT_ZERO. Fixes are delivered through standard kernel errata for supported products. Operational exposure depends on whether this subsystem or driver is active in your configuration.

Red Hat mitigation

To mitigate this issue, prevent the i3c_mipi_i3c_hci module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 8, 2026
Updated Aug 5, 2026
Reserved May 1, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 8, 2026
ENISA EUVD
Assigner Linux
Published May 8, 2026
Updated Aug 5, 2026
Exploited since n/a
EUVD-2026-28658