CVE-2026-93199 PUBLISHED

i3c: master: Do not treat master device as a duplicate target

Assigner: Linux
Reserved: 17.09.2026 Published: 17.09.2026 Updated: 17.09.2026

In the Linux kernel, the following vulnerability has been resolved:

i3c: master: Do not treat master device as a duplicate target

i3c_master_search_i3c_dev_duplicate() searches the bus for another I3C device with the same PID as the reference device. The search can match master->this, causing the controller itself to be returned as a duplicate.

Since the controller is not a target device, it cannot be a duplicate of one. Exclude master->this from matching so that the function only returns real duplicate target devices.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 to d0cc00957292e353ad46039034cd8f82fc4f8057 (excl.)
  • affected from 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 to 150e71808d3715a0deefbb189c780d03fdbdc735 (excl.)
  • affected from 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 to 4dc1b3eeba7991905a5b5b8129ebea51be7d87b7 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.0 is affected
  • unaffected from 0 to 5.0 (excl.)
  • unaffected from 6.18.52 to 6.18.* (incl.)
  • unaffected from 7.2.6 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References