i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue
Published May 8, 2026
7.8
HIGHCVSS 3.1
EPSS 0.17%
Description
The logic used to abort the DMA ring contains several flaws:
1. The driver unconditionally issues a ring abort even when the ring has already stopped. 2. The completion used to wait for abort completion is never re-initialized, resulting in incorrect wait behavior. 3. The abort sequence unintentionally clears RING_CTRL_ENABLE, which resets hardware ring pointers and disrupts the controller state. 4. If the ring is already stopped, the abort operation should be considered successful without attempting further action.
Fix the abort handling by checking whether the ring is running before issuing an abort, re-initializing the completion when needed, ensuring that RING_CTRL_ENABLE remains asserted during abort, and treating an already stopped ring as a successful condition.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.11StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.11
- Version 6.18.19StatusunaffectedConstraints<=6.18.*
- Version 6.19.9StatusunaffectedConstraints<=6.19.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.11 · < 6.18.19
- ≥ 6.19 · < 6.19.9
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat acknowledges the upstream Linux kernel correction for «i3c» as described in COMMENT_ZERO. Fixes are delivered through standard kernel errata for supported products. Operational exposure depends on whether this subsystem or driver is active in your configuration.
Red Hat mitigation
To mitigate this issue, prevent the i3c_mipi_i3c_hci module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-43352 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468177 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28658 Advisory
- https://git.kernel.org/stable/c/003df94bcc9227e8e930abd03ac7f63ac10033dc Patch
- https://git.kernel.org/stable/c/5549611888f5ca2db5e8e692b57f30626ddf9898 Patch
- https://git.kernel.org/stable/c/b795e68bf3073d67bebbb5a44d93f49efc5b8cc7 Patch
- https://lore.kernel.org/linux-cve-announce/2026050823-CVE-2026-43352-73ed@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-43352
- https://www.cve.org/CVERecord?id=CVE-2026-43352
Change history (0)
No recorded changes yet.