{"api_version":"1","generated_at":"2026-10-08T19:59:38+00:00","cve":"CVE-2026-93287","urls":{"html":"https://cve.report/CVE-2026-93287","api":"https://cve.report/api/cve/CVE-2026-93287.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93287","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93287"},"summary":{"title":"i2c: smbus: reject oversized block transfers in the common path","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: smbus: reject oversized block transfers in the common path\n\nThe SMBus block transfer length data->block[0] is validated in\ni2c_smbus_xfer_emulated() but that check runs too late for tracepoints\nand is skipped entirely when the adapter provides a native smbus_xfer\nimplementation. This allows user-controlled oversized block lengths to\nreach tracepoint memcpy calls and driver callbacks unchecked.\n\nAdd an early validation in __i2c_smbus_xfer() that rejects block\ntransfers whose caller-supplied length is zero or exceeds\nI2C_SMBUS_BLOCK_MAX before any tracepoint fires or driver callback\nruns. data->block[0] is filled in by the device on SMBus block reads,\nso the check is scoped to operations where the length is actually\nsupplied by the caller. This is consistent with the existing -EINVAL\nconvention in the emulated path and protects all downstream consumers\nat once: the smbus_write tracepoint, all native smbus_xfer driver\nimplementations, and the emulated path.\n\nTwo distinct bugs are fixed by this change:\n\nBug 1: smbus_write tracepoint OOB (include/trace/events/smbus.h)\n  trace_smbus_write() fires before any validation and copies\n  data->block[0]+1 bytes into a 34-byte event buffer. With\n  block[0]=0xfe the tracepoint copies 255 bytes, overflowing by 221.\n\n BUG: KASAN: stack-out-of-bounds in trace_event_raw_event_smbus_write+0x27c/0x530\n Read of size 255 at addr ffff88800d98fcf8 by task poc_smbus/91\n Call Trace:\n  <TASK>\n  __asan_memcpy+0x23/0x80\n  trace_event_raw_event_smbus_write+0x27c/0x530\n  __i2c_smbus_xfer+0x43a/0xa40\n  i2c_smbus_xfer+0x19e/0x340\n  i2cdev_ioctl_smbus+0x38f/0x7f0\n  i2cdev_ioctl+0x35e/0x680\n  __x64_sys_ioctl+0x147/0x1e0\n  do_syscall_64+0xcf/0x15a0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  </TASK>\n\nBug 2: i2c-stub I2C_SMBUS_I2C_BLOCK_DATA OOB (drivers/i2c/i2c-stub.c)\n  stub_xfer() implements .smbus_xfer directly and only clamps\n  block[0] against 256-command, not I2C_SMBUS_BLOCK_MAX. With\n  block[0]=0xff and command=0 the loop accesses block[1+i] for\n  i up to 254, far past the 34-byte union.\n\n UBSAN: array-index-out-of-bounds in drivers/i2c/i2c-stub.c:223:44\n index 34 is out of range for type '__u8 [34]'\n Call Trace:\n  <TASK>\n  __ubsan_handle_out_of_bounds+0xd7/0x120\n  stub_xfer+0x1971/0x198f [i2c_stub]\n  __i2c_smbus_xfer+0x306/0xa40\n  i2c_smbus_xfer+0x19e/0x340\n  i2cdev_ioctl_smbus+0x38f/0x7f0\n  i2cdev_ioctl+0x35e/0x680\n  __x64_sys_ioctl+0x147/0x1e0\n  do_syscall_64+0xcf/0x15a0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  </TASK>\n\nBoth traces reproduced on v7.0-rc6+i2c/for-current with KASAN+UBSAN.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 17:17:09","updated_at":"2026-10-03 11:17:47"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/f09edffba97d37b1fdff5f818a9a45f8a98ac171","name":"https://git.kernel.org/stable/c/f09edffba97d37b1fdff5f818a9a45f8a98ac171","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/72ca5e0b8b7a62615758f8871c34d61616c2dc8b","name":"https://git.kernel.org/stable/c/72ca5e0b8b7a62615758f8871c34d61616c2dc8b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/856dffcc097b3d8ed45a643ebda07cb92968cb33","name":"https://git.kernel.org/stable/c/856dffcc097b3d8ed45a643ebda07cb92968cb33","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/356875e33f2c6d2061a02c9dec1a1e639d265a55","name":"https://git.kernel.org/stable/c/356875e33f2c6d2061a02c9dec1a1e639d265a55","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c4b478bc50b7ca9865e237909941253a0f7111a2","name":"https://git.kernel.org/stable/c/c4b478bc50b7ca9865e237909941253a0f7111a2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3051cd060fa496df42954291fa2306ed2eab4ecc","name":"https://git.kernel.org/stable/c/3051cd060fa496df42954291fa2306ed2eab4ecc","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/df077253f6405d67ad087538e495ef32a05717b7","name":"https://git.kernel.org/stable/c/df077253f6405d67ad087538e495ef32a05717b7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93287","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93287","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4710317891e4824ce1510a6b5066abbd3e917750 856dffcc097b3d8ed45a643ebda07cb92968cb33 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4710317891e4824ce1510a6b5066abbd3e917750 356875e33f2c6d2061a02c9dec1a1e639d265a55 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4710317891e4824ce1510a6b5066abbd3e917750 72ca5e0b8b7a62615758f8871c34d61616c2dc8b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4710317891e4824ce1510a6b5066abbd3e917750 df077253f6405d67ad087538e495ef32a05717b7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4710317891e4824ce1510a6b5066abbd3e917750 f09edffba97d37b1fdff5f818a9a45f8a98ac171 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4710317891e4824ce1510a6b5066abbd3e917750 c4b478bc50b7ca9865e237909941253a0f7111a2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4710317891e4824ce1510a6b5066abbd3e917750 3051cd060fa496df42954291fa2306ed2eab4ecc git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.33","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.33 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.271 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.222 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.189 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.158 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"93287","cve":"CVE-2026-93287","epss":"0.001290000","percentile":"0.021790000","score_date":"2026-10-05","updated_at":"2026-10-06 00:14:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/i2c/i2c-core-smbus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"856dffcc097b3d8ed45a643ebda07cb92968cb33","status":"affected","version":"4710317891e4824ce1510a6b5066abbd3e917750","versionType":"git"},{"lessThan":"356875e33f2c6d2061a02c9dec1a1e639d265a55","status":"affected","version":"4710317891e4824ce1510a6b5066abbd3e917750","versionType":"git"},{"lessThan":"72ca5e0b8b7a62615758f8871c34d61616c2dc8b","status":"affected","version":"4710317891e4824ce1510a6b5066abbd3e917750","versionType":"git"},{"lessThan":"df077253f6405d67ad087538e495ef32a05717b7","status":"affected","version":"4710317891e4824ce1510a6b5066abbd3e917750","versionType":"git"},{"lessThan":"f09edffba97d37b1fdff5f818a9a45f8a98ac171","status":"affected","version":"4710317891e4824ce1510a6b5066abbd3e917750","versionType":"git"},{"lessThan":"c4b478bc50b7ca9865e237909941253a0f7111a2","status":"affected","version":"4710317891e4824ce1510a6b5066abbd3e917750","versionType":"git"},{"lessThan":"3051cd060fa496df42954291fa2306ed2eab4ecc","status":"affected","version":"4710317891e4824ce1510a6b5066abbd3e917750","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/i2c/i2c-core-smbus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.33"},{"lessThan":"2.6.33","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.271","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.222","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.189","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.158","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.271","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.222","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.189","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.158","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"2.6.33","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: smbus: reject oversized block transfers in the common path\n\nThe SMBus block transfer length data->block[0] is validated in\ni2c_smbus_xfer_emulated() but that check runs too late for tracepoints\nand is skipped entirely when the adapter provides a native smbus_xfer\nimplementation. This allows user-controlled oversized block lengths to\nreach tracepoint memcpy calls and driver callbacks unchecked.\n\nAdd an early validation in __i2c_smbus_xfer() that rejects block\ntransfers whose caller-supplied length is zero or exceeds\nI2C_SMBUS_BLOCK_MAX before any tracepoint fires or driver callback\nruns. data->block[0] is filled in by the device on SMBus block reads,\nso the check is scoped to operations where the length is actually\nsupplied by the caller. This is consistent with the existing -EINVAL\nconvention in the emulated path and protects all downstream consumers\nat once: the smbus_write tracepoint, all native smbus_xfer driver\nimplementations, and the emulated path.\n\nTwo distinct bugs are fixed by this change:\n\nBug 1: smbus_write tracepoint OOB (include/trace/events/smbus.h)\n  trace_smbus_write() fires before any validation and copies\n  data->block[0]+1 bytes into a 34-byte event buffer. With\n  block[0]=0xfe the tracepoint copies 255 bytes, overflowing by 221.\n\n BUG: KASAN: stack-out-of-bounds in trace_event_raw_event_smbus_write+0x27c/0x530\n Read of size 255 at addr ffff88800d98fcf8 by task poc_smbus/91\n Call Trace:\n  <TASK>\n  __asan_memcpy+0x23/0x80\n  trace_event_raw_event_smbus_write+0x27c/0x530\n  __i2c_smbus_xfer+0x43a/0xa40\n  i2c_smbus_xfer+0x19e/0x340\n  i2cdev_ioctl_smbus+0x38f/0x7f0\n  i2cdev_ioctl+0x35e/0x680\n  __x64_sys_ioctl+0x147/0x1e0\n  do_syscall_64+0xcf/0x15a0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  </TASK>\n\nBug 2: i2c-stub I2C_SMBUS_I2C_BLOCK_DATA OOB (drivers/i2c/i2c-stub.c)\n  stub_xfer() implements .smbus_xfer directly and only clamps\n  block[0] against 256-command, not I2C_SMBUS_BLOCK_MAX. With\n  block[0]=0xff and command=0 the loop accesses block[1+i] for\n  i up to 254, far past the 34-byte union.\n\n UBSAN: array-index-out-of-bounds in drivers/i2c/i2c-stub.c:223:44\n index 34 is out of range for type '__u8 [34]'\n Call Trace:\n  <TASK>\n  __ubsan_handle_out_of_bounds+0xd7/0x120\n  stub_xfer+0x1971/0x198f [i2c_stub]\n  __i2c_smbus_xfer+0x306/0xa40\n  i2c_smbus_xfer+0x19e/0x340\n  i2cdev_ioctl_smbus+0x38f/0x7f0\n  i2cdev_ioctl+0x35e/0x680\n  __x64_sys_ioctl+0x147/0x1e0\n  do_syscall_64+0xcf/0x15a0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  </TASK>\n\nBoth traces reproduced on v7.0-rc6+i2c/for-current with KASAN+UBSAN."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - Attacker-controlled data is data->block[0] copied from the I2C_SMBUS ioctl in i2cdev_ioctl_smbus() (i2cdev_ioctl → i2cdev_ioctl_smbus → i2c_smbus_xfer → __i2c_smbus_xfer). That byte is supplied by the local process, not by a network protocol or a remote I2C slave.\nAC:L - A single I2C_SMBUS ioctl with attacker-chosen block[0] (e.g. 0xfe) is consumed in __i2c_smbus_xfer() before any length check, so trace_smbus_write() memcpy()s block[0]+1 bytes and native callbacks such as stub_xfer() index block[1+i] with that length. There is no race or uninfluenced hardware failure.\nPR:L - i2cdev_open() and i2cdev_ioctl() contain no capable() check; I2C_SMBUS is allowed to whoever can open /dev/i2c-N. That node is commonly 0660 group i2c (i2c-tools udev), so an unprivileged i2c-group user reaches i2cdev_ioctl_smbus() without root or a user-namespace capability.\nUI:N - The attacker opens /dev/i2c-N and issues the I2C_SMBUS ioctl with a crafted i2c_smbus_ioctl_data themselves; no separate victim action is required.\nS:U - Overflows land in the host kernel's i2cdev_ioctl_smbus() stack union and in the smbus_write trace-event buffer handled by that same kernel. This is ordinary local kernel memory corruption, not a VM, IOMMU, or sandbox-authority crossing.\nC:H - With block[0]=0xfe, trace_smbus_write() memcpy()s 255 bytes from the 34-byte union i2c_smbus_data temp on i2cdev_ioctl_smbus()'s stack, disclosing 221 bytes of adjacent kernel stack. stub_xfer() I2C_SMBUS_I2C_BLOCK_DATA writes likewise read block[1+i] past that union.\nI:H - The same memcpy writes 255 bytes into smbus_write's 34-byte __entry->buf, overflowing the ftrace event by 221 bytes. stub_xfer() I2C_SMBUS_I2C_BLOCK_DATA reads write past temp.block[33] on i2cdev_ioctl_smbus()'s kernel stack, a stack overflow that can corrupt return state.\nA:H - The 221-byte out-of-bounds read/write in trace_event_raw_event_smbus_write() and the stub_xfer() store past union i2c_smbus_data.block[33] produce a kernel oops/panic, matching the KASAN and UBSAN reports cited in the fix."}]}],"providerMetadata":{"dateUpdated":"2026-10-03T10:57:13.466Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/856dffcc097b3d8ed45a643ebda07cb92968cb33"},{"url":"https://git.kernel.org/stable/c/356875e33f2c6d2061a02c9dec1a1e639d265a55"},{"url":"https://git.kernel.org/stable/c/72ca5e0b8b7a62615758f8871c34d61616c2dc8b"},{"url":"https://git.kernel.org/stable/c/df077253f6405d67ad087538e495ef32a05717b7"},{"url":"https://git.kernel.org/stable/c/f09edffba97d37b1fdff5f818a9a45f8a98ac171"},{"url":"https://git.kernel.org/stable/c/c4b478bc50b7ca9865e237909941253a0f7111a2"},{"url":"https://git.kernel.org/stable/c/3051cd060fa496df42954291fa2306ed2eab4ecc"}],"title":"i2c: smbus: reject oversized block transfers in the common path","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93287","datePublished":"2026-09-24T16:02:11.296Z","dateReserved":"2026-09-17T16:02:15.099Z","dateUpdated":"2026-10-03T10:57:13.466Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 17:17:09","lastModifiedDate":"2026-10-03 11:17:47","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93287","Ordinal":"1","Title":"i2c: smbus: reject oversized block transfers in the common path","CVE":"CVE-2026-93287","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93287","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: smbus: reject oversized block transfers in the common path\n\nThe SMBus block transfer length data->block[0] is validated in\ni2c_smbus_xfer_emulated() but that check runs too late for tracepoints\nand is skipped entirely when the adapter provides a native smbus_xfer\nimplementation. This allows user-controlled oversized block lengths to\nreach tracepoint memcpy calls and driver callbacks unchecked.\n\nAdd an early validation in __i2c_smbus_xfer() that rejects block\ntransfers whose caller-supplied length is zero or exceeds\nI2C_SMBUS_BLOCK_MAX before any tracepoint fires or driver callback\nruns. data->block[0] is filled in by the device on SMBus block reads,\nso the check is scoped to operations where the length is actually\nsupplied by the caller. This is consistent with the existing -EINVAL\nconvention in the emulated path and protects all downstream consumers\nat once: the smbus_write tracepoint, all native smbus_xfer driver\nimplementations, and the emulated path.\n\nTwo distinct bugs are fixed by this change:\n\nBug 1: smbus_write tracepoint OOB (include/trace/events/smbus.h)\n  trace_smbus_write() fires before any validation and copies\n  data->block[0]+1 bytes into a 34-byte event buffer. With\n  block[0]=0xfe the tracepoint copies 255 bytes, overflowing by 221.\n\n BUG: KASAN: stack-out-of-bounds in trace_event_raw_event_smbus_write+0x27c/0x530\n Read of size 255 at addr ffff88800d98fcf8 by task poc_smbus/91\n Call Trace:\n  <TASK>\n  __asan_memcpy+0x23/0x80\n  trace_event_raw_event_smbus_write+0x27c/0x530\n  __i2c_smbus_xfer+0x43a/0xa40\n  i2c_smbus_xfer+0x19e/0x340\n  i2cdev_ioctl_smbus+0x38f/0x7f0\n  i2cdev_ioctl+0x35e/0x680\n  __x64_sys_ioctl+0x147/0x1e0\n  do_syscall_64+0xcf/0x15a0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  </TASK>\n\nBug 2: i2c-stub I2C_SMBUS_I2C_BLOCK_DATA OOB (drivers/i2c/i2c-stub.c)\n  stub_xfer() implements .smbus_xfer directly and only clamps\n  block[0] against 256-command, not I2C_SMBUS_BLOCK_MAX. With\n  block[0]=0xff and command=0 the loop accesses block[1+i] for\n  i up to 254, far past the 34-byte union.\n\n UBSAN: array-index-out-of-bounds in drivers/i2c/i2c-stub.c:223:44\n index 34 is out of range for type '__u8 [34]'\n Call Trace:\n  <TASK>\n  __ubsan_handle_out_of_bounds+0xd7/0x120\n  stub_xfer+0x1971/0x198f [i2c_stub]\n  __i2c_smbus_xfer+0x306/0xa40\n  i2c_smbus_xfer+0x19e/0x340\n  i2cdev_ioctl_smbus+0x38f/0x7f0\n  i2cdev_ioctl+0x35e/0x680\n  __x64_sys_ioctl+0x147/0x1e0\n  do_syscall_64+0xcf/0x15a0\n  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n  </TASK>\n\nBoth traces reproduced on v7.0-rc6+i2c/for-current with KASAN+UBSAN.","Type":"Description","Title":"i2c: smbus: reject oversized block transfers in the common path"}]}}}