CVE-2026-93199

Summary

In the Linux kernel, the following vulnerability has been resolved:

i3c: master: Do not treat master device as a duplicate target

i3c_master_search_i3c_dev_duplicate() searches the bus for another I3C device with the same PID as the reference device. The search can match master->this, causing the controller itself to be returned as a duplicate.

Since the controller is not a target device, it cannot be a duplicate of one. Exclude master->this from matching so that the function only returns real duplicate target devices.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 < d0cc00957292e353ad46039034cd8f82fc4f8057affected
LinuxLinux3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 < 150e71808d3715a0deefbb189c780d03fdbdc735affected
LinuxLinux3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 < 4dc1b3eeba7991905a5b5b8129ebea51be7d87b7affected
LinuxLinux5.0affected
LinuxLinux0 < 5.0unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References