CVE-2026-80953
In the Linux kernel, the following vulnerability has been resolved:
i3c: master: adi: initialize the lock before enabling interrupts
adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR before the controller's IBI state, transfer queue list and transfer queue lock are initialized. A pending CMDR interrupt can therefore run adi_i3c_master_irq() and take master->xferqueue.lock before the dynamic lock has been initialized.
This issue was found by our static analysis tool and then manually reviewed against the current tree.
The grounded PoC kept the probe ordering and the IRQ path adi_i3c_master_probe() -> adi_i3c_master_irq() -> xferqueue.lock, with a pending CMDR interrupt arriving after REG_IRQ_PENDING_CMDR is unmasked. Lockdep reported:
Leer descripción completaMostrar menos
Initialize the transfer queue and IBI state before requesting and unmasking the IRQ.
Detalles técnicos trazas, registros y código del informe original
INFO: trying to register non-static key. you didn't initialize this object before use? lock_acquire+0xbb/0x290 _raw_spin_lock_irqsave+0x36/0x60 adi_i3c_master_irq+0x32/0x56 [vuln_msv] adi_i3c_master_probe+0x5a/0xf47 [vuln_msv]
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Impacto principal
T1499.004Application or System Exploitationimpact65 %
Vulnerabilidad local (AV:L, PR:N, UI:N) en el kernel Linux que permite denegar servicio mediante un interrupt de CMDR no sincronizado que causa un bloqueo no inicializado, resultando en crash del sistema.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80953",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.4,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.5
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a79ac2cdc91d6be3010f2e9a3b2a2ccfc26e2086",
"lessThan": "a15a1b95de980362c14f32f519b293b0d12ce86f",
"versionType": "git"
},
{
"status": "affected",
"version": "a79ac2cdc91d6be3010f2e9a3b2a2ccfc26e2086",
"lessThan": "de8c32b0a246bbb4b44ec29e12769496a0bf66f7",
"versionType": "git"
},
{
"status": "affected",
"version": "a79ac2cdc91d6be3010f2e9a3b2a2ccfc26e2086",
"lessThan": "8a53f9102a0d3eeb8784999f925028acf339c276",
"versionType": "git"
}
],
"programFiles": [
"drivers/i3c/master/adi-i3c-master.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.18"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.18",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/i3c/master/adi-i3c-master.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:01.040",
"references": [
{
"url": "https://git.kernel.org/stable/c/8a53f9102a0d3eeb8784999f925028acf339c276",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a15a1b95de980362c14f32f519b293b0d12ce86f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/de8c32b0a246bbb4b44ec29e12769496a0bf66f7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: adi: initialize the lock before enabling interrupts\n\nadi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR\nbefore the controller's IBI state, transfer queue list and transfer\nqueue lock are initialized. A pending CMDR interrupt can therefore run\nadi_i3c_master_irq() and take master->xferqueue.lock before the dynamic\nlock has been initialized.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the probe ordering and the IRQ path\nadi_i3c_master_probe() -> adi_i3c_master_irq() -> xferqueue.lock, with a\npending CMDR interrupt arriving after REG_IRQ_PENDING_CMDR is unmasked.\nLockdep reported:\n\n INFO: trying to register non-static key.\n you didn't initialize this object before use?\n lock_acquire+0xbb/0x290\n _raw_spin_lock_irqsave+0x36/0x60\n adi_i3c_master_irq+0x32/0x56 [vuln_msv]\n adi_i3c_master_probe+0x5a/0xf47 [vuln_msv]\n\nInitialize the transfer queue and IBI state before requesting and\nunmasking the IRQ."
}
],
"lastModified": "2026-09-13T07:17:02.463",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}