CVE-2025-23147
Published: May 1, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: i3c: Add NULL pointer check in i3c_master_queue_ibi() The I3C master driver may receive an IBI from a target device that has not been probed yet. In such cases, the master calls `i3c_master_queue_ibi()` to queue an IBI work task, leading to "Unable to handle kernel read from unreadable memory" and resulting in a kernel panic. Typical IBI handling flow: 1. The I3C master scans target devices and probes their respective drivers. 2. The target device driver calls `i3c_device_request_ibi()` to enable IBI and assigns `dev->ibi = ibi`. 3. The I3C master receives an IBI from the target device and calls `i3c_master_queue_ibi()` to queue the target device driver’s IBI handler task. However, since target device events are asynchronous to the I3C probe sequence, step 3 may occur before step 2, causing `dev->ibi` to be `NULL`, leading to a kernel panic. Add a NULL pointer check in `i3c_master_queue_ibi()` to prevent accessing an uninitialized `dev->ibi`, ensuring stability.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 - < 1b54faa5f47fa7c642179744aeff03f0810dc62eaffected 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 - < 09359e7c8751961937cb5fc50220969b0a4e1058affected 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 - < 3ba402610843d7d15c7f3966a461deeeaff7fba4affected 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 - < d83b0c03ef8fbea2f03029a1cc1f5041f0e1d47faffected 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 - < 6871a676aa534e8f218279672e0445c725f81026+4 more versions |
Linux | Linux | affected 5.0unaffected 0 - < 5.0unaffected 5.4.293 - <= 5.4.*unaffected 5.10.237 - <= 5.10.*unaffected 5.15.181 - <= 5.15.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now