CVE-2026-43353 (GCVE-0-2026-43353)
Vulnerability from cvelistv5
Published
2026-05-08 14:21
Modified
2026-08-05 12:27
Summary
In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue The HCI DMA dequeue path (hci_dma_dequeue_xfer()) may be invoked for multiple transfers that timeout around the same time. However, the function is not serialized and can race with itself. When a timeout occurs, hci_dma_dequeue_xfer() stops the ring, processes incomplete transfers, and then restarts the ring. If another timeout triggers a parallel call into the same function, the two instances may interfere with each other - stopping or restarting the ring at unexpected times. Add a mutex so that hci_dma_dequeue_xfer() is serialized with respect to itself.
Impacted products
Vendor Product Version
Linux Linux Version: 9ad9a52cce2828d932ae9495181e3d6414f72c07
Version: 9ad9a52cce2828d932ae9495181e3d6414f72c07
Version: 9ad9a52cce2828d932ae9495181e3d6414f72c07
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/i3c/master/mipi-i3c-hci/core.c",
            "drivers/i3c/master/mipi-i3c-hci/dma.c",
            "drivers/i3c/master/mipi-i3c-hci/hci.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "b684b420a5bb0ea1b0e13abfdb8ce41c5266e62e",
              "status": "affected",
              "version": "9ad9a52cce2828d932ae9495181e3d6414f72c07",
              "versionType": "git"
            },
            {
              "lessThan": "4faa1e9c67a2229f6749190aedaf88ce0391efd2",
              "status": "affected",
              "version": "9ad9a52cce2828d932ae9495181e3d6414f72c07",
              "versionType": "git"
            },
            {
              "lessThan": "1dca8aee80eea76d2aae21265de5dd64f6ba0f09",
              "status": "affected",
              "version": "9ad9a52cce2828d932ae9495181e3d6414f72c07",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/i3c/master/mipi-i3c-hci/core.c",
            "drivers/i3c/master/mipi-i3c-hci/dma.c",
            "drivers/i3c/master/mipi-i3c-hci/hci.h"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.11"
            },
            {
              "lessThan": "5.11",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.19",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.9",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.19",
                  "versionStartIncluding": "5.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.9",
                  "versionStartIncluding": "5.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "5.11",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Fix race in DMA ring dequeue\n\nThe HCI DMA dequeue path (hci_dma_dequeue_xfer()) may be invoked for\nmultiple transfers that timeout around the same time.  However, the\nfunction is not serialized and can race with itself.\n\nWhen a timeout occurs, hci_dma_dequeue_xfer() stops the ring, processes\nincomplete transfers, and then restarts the ring.  If another timeout\ntriggers a parallel call into the same function, the two instances may\ninterfere with each other - stopping or restarting the ring at unexpected\ntimes.\n\nAdd a mutex so that hci_dma_dequeue_xfer() is serialized with respect to\nitself."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable DMA dequeue path is reached through local kernel I3C/I2C transfer APIs, including userspace-triggerable device/client paths on systems exposing I3C-backed devices. There is no evidence of direct internet/network packet reachability for this HCI master driver.\nAC:L - The I3C core explicitly permits parallel normal transfers, and the bug is a missing serialization primitive when multiple transfers time out together. An attacker who can trigger concurrent transfers can create the race rather than relying on an uncontrollable rare condition.\nPR:L - Reaching the path requires local ability to cause I3C/I2C client transfers, such as access to exposed device interfaces or subsystem clients, but no kernel capability check is present in the vulnerable HCI dequeue logic itself. This is best treated as low local privilege rather than real administrator/root-only privilege.\nUI:N - Once the attacker can trigger the relevant transfers, no separate victim action is required. The timeout/dequeue handling runs in the kernel as part of transfer completion/error handling.\nS:U - The vulnerability corrupts or destabilizes kernel-controlled I3C HCI/DMA state within the same kernel security authority. It does not constitute a VM escape or an IOMMU/DMA isolation boundary bypass by itself.\nC:H - The race can restart or manipulate a DMA ring while another dequeue path is still aborting, replacing descriptors, and unmapping DMA buffers, leaving hardware able to access stale or unintended kernel memory. Under the required overestimate rule, this DMA memory corruption is treated as capable of high confidentiality impact.\nI:H - The same stale descriptor/unmap race can allow device DMA or ring state corruption to write into unintended or freed kernel memory. That is a memory corruption primitive, so high integrity impact is defensible.\nA:H - The vulnerable path can leave the DMA ring and host controller in an inconsistent state, trigger WARN/oops-like failure paths, or cause DMA/ring corruption. A kernel crash, hang, or persistent controller failure gives high availability impact."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:27:27.095Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b684b420a5bb0ea1b0e13abfdb8ce41c5266e62e"
        },
        {
          "url": "https://git.kernel.org/stable/c/4faa1e9c67a2229f6749190aedaf88ce0391efd2"
        },
        {
          "url": "https://git.kernel.org/stable/c/1dca8aee80eea76d2aae21265de5dd64f6ba0f09"
        }
      ],
      "title": "i3c: mipi-i3c-hci: Fix race in DMA ring dequeue",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-43353",
    "datePublished": "2026-05-08T14:21:10.282Z",
    "dateReserved": "2026-05-01T14:12:56.005Z",
    "dateUpdated": "2026-08-05T12:27:27.095Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…