PT-2026-94734 · Linux · Linux Kernel

CVE-2026-90386

·

Published

2026-09-17

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0.11-200.fc44.x86 64
Description A shift-out-of-bounds issue exists in the i3c dw driver. When the ENTDAA process assigns no devices on an empty bus, the cmd->rx len variable equals master->maxdevs. This causes the GENMASK() index to become -1, leading to a shift exponent of 64, which is too large for a 64-bit long unsigned int type. This condition triggers UBSAN (Undefined Behavior Sanitizer), a tool used to detect undefined behavior in C/C++ programs.
Recommendations Update to Linux kernel version 7.0.11-200.fc44.x86 64 or later.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102134
CVE-2026-90386
OPENSUSE-SU-2026:11893-1
USN-8800-1

Affected Products

Linux Kernel