Back

HIGH

i3c: renesas: Check that the transfer is valid before accessing it

Published Sep 11, 2026

Description

The Renesas I3C driver uses an asynchronous model to transfer data. It prepares a struct renesas_i3c_xfer, enqueues it, and waits for completion. The interrupt handler dequeues the transfer, updates/uses it, and signals the waiting thread.

If the completion times out, the waiting thread dequeues the transfer and free it. If an interrupt fires after that, the handler may access freed memory, leading to crashes.

Check that the transfer is still valid before accessing it in the interrupt handler. With it clear any status flags and disable all the interrupts to avoid triggering the same interrupts again.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 11, 2026
Updated Sep 13, 2026
Reserved Aug 26, 2026
NVD
Status Received
Modified Sep 13, 2026
Red Hat
Severity Moderate
Public date Sep 11, 2026
ENISA EUVD
Assigner Linux
Published Sep 11, 2026
Updated Sep 13, 2026
Exploited since n/a
EUVD-2026-76273