CVE-2026-90386
CVE CVE-2026-90386EUVD EUVD-2026-82047Published 2026-09-17T16:09:21.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices On an empty bus ENTDAA assigns nothing, so cmd->rx_len (the count of addresses left unassigned) equals master->maxdevs. The GENMASK() index master->maxdevs - cmd->rx_len - 1 then becomes -1, which trips up UBSAN. This happens every time on boot on a Gigabyte/AMD server: UBSAN: shift-out-of-bounds in drivers/i3c/master/dw-i3c-master.c:905:12 shift exponent 64 is too large for 64-bit type 'long unsigned int' CPU: 7 UID: 0 PID: 963 Comm: (udev-worker) Not tainted 7.0.11-200.fc44.x86_64 #1 PREEMPT(lazy) Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R32_F45 04/01/2026 Call Trace: <TASK> dump_stack_lvl+0x5d/0x80 ubsan_epilogue+0x5/0x2b __ubsan_handle_shift_out_of_bounds.cold+0xd7/0x1ab dw_i3c_master_daa.cold+0x1b/0x96 [dw_i3c_master] i3c_master_do_daa_ext.part.0+0x3e/0xf0 [i3c] Skip the mask when no new device was assigned.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.6.157; patch: 0; patch: 5.10.270; 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef <111f559e5b6461f5f6977275716e6c5d1eb7ea27; patch: 6.1.188; 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef <754533e6169d1f10bdef7a6ba9bd7740b524e1d4; 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef <63110ccc434e10d9e9d2c7d82ebfa8a6f9cedd94; 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef <5650b013e6bfc14c8b30be727f4a715b01860a08; 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef <3a1c35739efb69e8ec2a868113a0471a01bb8f29; patch: 6.18.52; 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef <618dd640ded6b94bbdb79c798a901ec564797033; 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef <038cf48b3170af26a70bf2dee4f8c3ac910f5176; patch: 7.2.6; patch: 6.12.110; 5.0; patch: 7.3-rc1; 1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef <9eaac0cb4ca94e2e32c53c156ae5b813ba7ef90c; patch: 5.15.221
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.