mctp i2c: initialise event handler read bytes
Published May 27, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.16%
Description
Set a 0xff value for i2c reads of an mctp-i2c device. Otherwise reads will return "val" from the i2c bus driver. For i2c-aspeed and i2c-npcm7xx that is a stack uninitialised u8.
Tested with "i2ctransfer -y 1 r10@0x34" where 0x34 is a mctp-i2c instance, now it returns all 0xff.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.18
Unaffected
- ≥ 0, < 5.18
- ≥ 6.1.165, ≤ 6.1.*
- ≥ 6.12.75, ≤ 6.12.*
- ≥ 6.18.14, ≤ 6.18.*
- ≥ 6.19.4, ≤ 6.19.*
- ≥ 6.6.128, ≤ 6.6.*
- 7.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 5.18 · < 6.1.165
- ≥ 6.2 · < 6.6.128
- ≥ 6.7 · < 6.12.75
- ≥ 6.13 · < 6.18.14
- ≥ 6.19 · < 6.19.4
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-45865 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2481978 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32331 Advisory
- https://git.kernel.org/stable/c/11f83253244060b5de5eac787f61ae3f3e559d01 Patch
- https://git.kernel.org/stable/c/1eeedb310229bfee9dd4d992e5bba33fe1378a8f Patch
- https://git.kernel.org/stable/c/2a14e91b6d76639dac70ea170f4384c1ee3cb48d Patch
- https://git.kernel.org/stable/c/6ff2ebfef75fbc57d937d8fbe738b967edf2d331 Patch
- https://git.kernel.org/stable/c/93e01e837e105299f1c259ef71f6e1ec4fe806e3 Patch
- https://git.kernel.org/stable/c/fa9861e5c8af7651dddfa8d490aaada17ae33b6c Patch
- https://lore.kernel.org/linux-cve-announce/2026052711-CVE-2026-45865-87b8@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-45865
- https://www.cve.org/CVERecord?id=CVE-2026-45865
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data