i3c: mipi-i3c-hci: Fix race in DMA ring dequeue
Published May 8, 2026
7.8
HIGHCVSS 3.1
EPSS 0.13%
Description
The HCI DMA dequeue path (hci_dma_dequeue_xfer()) may be invoked for multiple transfers that timeout around the same time. However, the function is not serialized and can race with itself.
When a timeout occurs, hci_dma_dequeue_xfer() stops the ring, processes incomplete transfers, and then restarts the ring. If another timeout triggers a parallel call into the same function, the two instances may interfere with each other - stopping or restarting the ring at unexpected times.
Add a mutex so that hci_dma_dequeue_xfer() is serialized with respect to itself.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.11StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.11
- Version 6.18.19StatusunaffectedConstraints<=6.18.*
- Version 6.19.9StatusunaffectedConstraints<=6.19.*
- Version 7.0StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.11 · < 6.18.19
- ≥ 6.19 · < 6.19.9
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat acknowledges the upstream Linux kernel correction for «i3c» as described in COMMENT_ZERO. Fixes are delivered through standard kernel errata for supported products. Operational exposure depends on whether this subsystem or driver is active in your configuration.
Red Hat mitigation
To mitigate this issue, prevent the i3c_mipi_i3c_hci module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-43353 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2468222 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28659 Advisory
- https://git.kernel.org/stable/c/1dca8aee80eea76d2aae21265de5dd64f6ba0f09 Patch
- https://git.kernel.org/stable/c/4faa1e9c67a2229f6749190aedaf88ce0391efd2 Patch
- https://git.kernel.org/stable/c/b684b420a5bb0ea1b0e13abfdb8ce41c5266e62e Patch
- https://lore.kernel.org/linux-cve-announce/2026050823-CVE-2026-43353-06fc@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-43353
- https://www.cve.org/CVERecord?id=CVE-2026-43353
Change history (0)
No recorded changes yet.