CVE-2026-97515
In the Linux kernel, the following vulnerability has been resolved:
i3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845
On NPCM845, when a target on the I3C bus gets stuck holding SDA low, the controller reports a false Master Request (MR) in-band interrupt event. The driver handles this by emitting a STOP condition to restore the bus.
However, the hardware quirk SVC_I3C_QUIRK_FALSE_SLVSTART indicates that emitting a STOP condition may spuriously set the SLVSTART interrupt status bit.
Leer descripción completaMostrar menos
In the Master Request case, this creates a feedback loop: the STOP triggers a new SLVSTART event, the IRQ handler fires again, the controller still reports an MR type, another STOP is emitted, and the cycle repeats indefinitely, resulting in an IRQ storm that can lock up the CPU.
Clear the SLVSTART status bit explicitly after emitting the STOP in the Master Request IBI handler when the SVC_I3C_QUIRK_FALSE_SLVSTART quirk is set. This breaks the feedback loop without affecting normal SLVSTART processing, which is already guarded in the top-level IRQ handler by checking that MSTATUS is in SLVREQ state.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.14%
- Percentil entre todas las CVEs puntuadas: 3
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97515",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "0430bf9bc1ac068c8b8c540eb93e5751872efc51",
"lessThan": "e9b139c4684ed8593a0b779ca02ea05f460b2eec",
"versionType": "git"
},
{
"status": "affected",
"version": "0430bf9bc1ac068c8b8c540eb93e5751872efc51",
"lessThan": "1effa3adfe53cb2bb28bf5640a676b791d5ab405",
"versionType": "git"
},
{
"status": "affected",
"version": "30748ce7e156f221fb91689b338a0d7df77b732a",
"versionType": "git"
},
{
"status": "affected",
"version": "f2985a1de6f53abbc42c7a696ee6ba8bdecc9426",
"versionType": "git"
},
{
"status": "affected",
"version": "0541822045ae043d62c941ca31fa76871e436b5e",
"versionType": "git"
},
{
"status": "affected",
"version": "1ea4653cff35c29d1dd0b14ad9c8245e7318f337",
"versionType": "git"
},
{
"status": "affected",
"version": "d231fb443d8d4042f0dd705b93beba8c916a7344",
"versionType": "git"
},
{
"status": "affected",
"version": "5.15.185",
"lessThan": "5.16",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.141",
"lessThan": "6.2",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.93",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.31",
"lessThan": "6.13",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.14.9",
"lessThan": "6.15",
"versionType": "semver"
}
],
"programFiles": [
"drivers/i3c/master/svc-i3c-master.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/i3c/master/svc-i3c-master.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:29.440",
"references": [
{
"url": "https://git.kernel.org/stable/c/1effa3adfe53cb2bb28bf5640a676b791d5ab405",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e9b139c4684ed8593a0b779ca02ea05f460b2eec",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845\n\nOn NPCM845, when a target on the I3C bus gets stuck holding SDA low,\nthe controller reports a false Master Request (MR) in-band interrupt\nevent. The driver handles this by emitting a STOP condition to restore\nthe bus.\n\nHowever, the hardware quirk SVC_I3C_QUIRK_FALSE_SLVSTART indicates that\nemitting a STOP condition may spuriously set the SLVSTART interrupt\nstatus bit. In the Master Request case, this creates a feedback loop:\nthe STOP triggers a new SLVSTART event, the IRQ handler fires again,\nthe controller still reports an MR type, another STOP is emitted, and\nthe cycle repeats indefinitely, resulting in an IRQ storm that can lock\nup the CPU.\n\nClear the SLVSTART status bit explicitly after emitting the STOP in the\nMaster Request IBI handler when the SVC_I3C_QUIRK_FALSE_SLVSTART quirk\nis set. This breaks the feedback loop without affecting normal SLVSTART\nprocessing, which is already guarded in the top-level IRQ handler by\nchecking that MSTATUS is in SLVREQ state."
}
],
"lastModified": "2026-09-28T06:16:37.523",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}