Back

MEDIUM

i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)

Published Aug 15, 2026

Description

SMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic (polling) path rejects it as -EPROTO. Worse, it returns without a NACK+STOP: the next receive cycle has already started, so the target keeps holding SDA and the bus stays stuck until a power cycle for this i2c controller.

Reading I2DR to obtain the count likewise arms the next byte on the count > I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly and left the bus held.

Handle both: NACK the in-flight dummy byte (TXAK) and extend msgs->len so the existing last-byte handling emits STOP; the dummy byte is discarded. A count of 0 is a valid empty block read; a count above I2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus has been released.

The interrupt-driven path has the same flaw from a later commit and is fixed separately, as it carries a different Fixes: tag and stable range.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Aug 15, 2026
Updated Aug 23, 2026
Reserved Aug 9, 2026
NVD
Status Received
Modified Aug 23, 2026
Red Hat
Severity Low
Public date Aug 15, 2026
ENISA EUVD
Assigner Linux
Published Aug 15, 2026
Updated Aug 23, 2026
Exploited since n/a
EUVD-2026-58900