CVE-2026-90386

Source
https://cve.org/CVERecord?id=CVE-2026-90386
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90386.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90386
Downstream
Published
2026-09-17T16:09:21Z
Modified
2026-09-18T03:48:37Z
Summary
i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices
Details

In the Linux kernel, the following vulnerability has been resolved:

i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices

On an empty bus ENTDAA assigns nothing, so cmd->rx_len (the count of addresses left unassigned) equals master->maxdevs.

The GENMASK() index master->maxdevs - cmd->rx_len - 1 then becomes -1, which trips up UBSAN. This happens every time on boot on a Gigabyte/AMD server:

UBSAN: shift-out-of-bounds in drivers/i3c/master/dw-i3c-master.c:905:12
shift exponent 64 is too large for 64-bit type 'long unsigned int'
CPU: 7 UID: 0 PID: 963 Comm: (udev-worker) Not tainted 7.0.11-200.fc44.x86_64 #1 PREEMPT(lazy)
Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R32_F45 04/01/2026
Call Trace:
 <TASK>
 dump_stack_lvl+0x5d/0x80
 ubsan_epilogue+0x5/0x2b
 __ubsan_handle_shift_out_of_bounds.cold+0xd7/0x1ab
 dw_i3c_master_daa.cold+0x1b/0x96 [dw_i3c_master]
 i3c_master_do_daa_ext.part.0+0x3e/0xf0 [i3c]

Skip the mask when no new device was assigned.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90386.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1dd728f5d4d4b8b53196c1e0fcf86bbaaee39cef
Fixed
5650b013e6bfc14c8b30be727f4a715b01860a08
Fixed
63110ccc434e10d9e9d2c7d82ebfa8a6f9cedd94
Fixed
3a1c35739efb69e8ec2a868113a0471a01bb8f29
Fixed
111f559e5b6461f5f6977275716e6c5d1eb7ea27
Fixed
754533e6169d1f10bdef7a6ba9bd7740b524e1d4
Fixed
9eaac0cb4ca94e2e32c53c156ae5b813ba7ef90c
Fixed
618dd640ded6b94bbdb79c798a901ec564797033
Fixed
038cf48b3170af26a70bf2dee4f8c3ac910f5176

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90386.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90386.json"