i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
Summary
| CVE | CVE-2026-52948 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-24 17:17:04 UTC |
| Updated | 2026-07-14 16:58:13 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzkaller, a persistent `schedule_timeout: wrong timeout value` warning was observed, accompanied by SMBus controller state machine corruption. The I2C_TIMEOUT ioctl accepts a user-provided timeout in multiples of 10 ms. The user argument is checked against INT_MAX, but it is subsequently multiplied by 10 before being passed to msecs_to_jiffies(). A malicious user can pass a large value (e.g., 429496729) that passes the `arg > INT_MAX` check but overflows when multiplied by 10. This results in a truncated 32-bit unsigned value that bypasses the internal `(int)m < 0` check in `msecs_to_jiffies()`. The truncated value is then assigned to `client->adapter->timeout` (a signed 32-bit int), which is reinterpreted as a negative number. When passed to wait_for_completion_timeout(), this negative value undergoes sign extension to a 64-bit unsigned long, triggering the `schedule_timeout` warning and causing premature returns. This leaves the SMBus state machine in an unrecoverable state, constituting a local Denial of Service (DoS). Fix this by bounding the user argument to `INT_MAX / 10`. [wsa: move the comment as well] |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.001850000 probability, percentile 0.082260000 (date 2026-07-13)
Problem Types: CWE-190
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected cd97f39b7cdf1c8a9c9f52865eec795b7f0c811d e9ffd5f5050fbb199d270a85614cd27ebed6fbac git | Not specified |
| CNA | Linux | Linux | affected cd97f39b7cdf1c8a9c9f52865eec795b7f0c811d 0b88ecfbc9dc33b4db8836c37b50cf174e6c0691 git | Not specified |
| CNA | Linux | Linux | affected cd97f39b7cdf1c8a9c9f52865eec795b7f0c811d 943e318eedbeaeea08ece3f5dd44c982f4ed2ef5 git | Not specified |
| CNA | Linux | Linux | affected cd97f39b7cdf1c8a9c9f52865eec795b7f0c811d aa6ef734016912653a909477fb30aeb66c98b3a2 git | Not specified |
| CNA | Linux | Linux | affected cd97f39b7cdf1c8a9c9f52865eec795b7f0c811d ff02add34ffd03449b8115904ebe2ec4fed022d4 git | Not specified |
| CNA | Linux | Linux | affected cd97f39b7cdf1c8a9c9f52865eec795b7f0c811d ffbcf31f032eb454ebfd29309f51366fe57f4ac4 git | Not specified |
| CNA | Linux | Linux | affected cd97f39b7cdf1c8a9c9f52865eec795b7f0c811d 4576621dc6577f21a032acfd16c3ad61907a5ea7 git | Not specified |
| CNA | Linux | Linux | affected cd97f39b7cdf1c8a9c9f52865eec795b7f0c811d 617eb7c0961a8dfcfc811844a6396e406b2923ea git | Not specified |
| CNA | Linux | Linux | affected 2.6.29 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.29 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.259 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.210 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.176 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.143 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.94 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.36 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.13 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/617eb7c0961a8dfcfc811844a6396e406b2923ea | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/e9ffd5f5050fbb199d270a85614cd27ebed6fbac | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/943e318eedbeaeea08ece3f5dd44c982f4ed2ef5 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/4576621dc6577f21a032acfd16c3ad61907a5ea7 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/aa6ef734016912653a909477fb30aeb66c98b3a2 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/ff02add34ffd03449b8115904ebe2ec4fed022d4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/0b88ecfbc9dc33b4db8836c37b50cf174e6c0691 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/ffbcf31f032eb454ebfd29309f51366fe57f4ac4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.