Back

HIGH

i3c: mipi-i3c-hci: Fix race in DMA ring dequeue

Published May 8, 2026

Description

The HCI DMA dequeue path (hci_dma_dequeue_xfer()) may be invoked for multiple transfers that timeout around the same time. However, the function is not serialized and can race with itself.

When a timeout occurs, hci_dma_dequeue_xfer() stops the ring, processes incomplete transfers, and then restarts the ring. If another timeout triggers a parallel call into the same function, the two instances may interfere with each other - stopping or restarting the ring at unexpected times.

Add a mutex so that hci_dma_dequeue_xfer() is serialized with respect to itself.

Affected products

Remediation

Red Hat statement

Red Hat acknowledges the upstream Linux kernel correction for «i3c» as described in COMMENT_ZERO. Fixes are delivered through standard kernel errata for supported products. Operational exposure depends on whether this subsystem or driver is active in your configuration.

Red Hat mitigation

To mitigate this issue, prevent the i3c_mipi_i3c_hci module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 8, 2026
Updated Aug 5, 2026
Reserved May 1, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 8, 2026
ENISA EUVD
Assigner Linux
Published May 8, 2026
Updated Aug 5, 2026
Exploited since n/a
EUVD-2026-28659