CVE-2026-90386 | Linux Kernel up to 7.2.5 dw-i3c-master dw-i3c-master.c dw_i3c_master_daa.cold rx_len/maxdevs out-of-bounds
A vulnerability was found in Linux Kernel up to 7.2.5. It has been rated as very critical. Affected by this vulnerability is the function dw_i3c_master_daa.cold of the file drivers/i3c/master/dw-i3c-master.c of the component dw-i3c-master. This manipulation of the argument rx_len/maxdevs causes out-of-bounds read.
This vulnerability is registered as CVE-2026-90386. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More