-

CVE-2026-72142

i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)

In the Linux kernel, the following vulnerability has been resolved:

i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)

SMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic
(polling) path rejects it as -EPROTO. Worse, it returns without a
NACK+STOP: the next receive cycle has already started, so the target
keeps holding SDA and the bus stays stuck until a power cycle for
this i2c controller.

Reading I2DR to obtain the count likewise arms the next byte on the
count > I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly
and left the bus held.

Handle both: NACK the in-flight dummy byte (TXAK) and extend msgs->len so
the existing last-byte handling emits STOP; the dummy byte is discarded.
A count of 0 is a valid empty block read; a count above
I2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus
has been released.

The interrupt-driven path has the same flaw from a later commit and is
fixed separately, as it carries a different Fixes: tag and stable range.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8e8782c71595a5ad29e234ce6b3d2fce787fb07a
Version < 0f29df3c3d607a9dbc14aed0e45504ced4d2e7ec
Status affected
Version 8e8782c71595a5ad29e234ce6b3d2fce787fb07a
Version < 38d4947431b2410850409fda016b2ac9f640a4dd
Status affected
Version 8e8782c71595a5ad29e234ce6b3d2fce787fb07a
Version < e3e8b02d4773cfc5ad561d2e5505efde36c6927a
Status affected
Version 8e8782c71595a5ad29e234ce6b3d2fce787fb07a
Version < 016ef0f6ca4bc9bf0330ac41bd2ea349759643e3
Status affected
Version 8e8782c71595a5ad29e234ce6b3d2fce787fb07a
Version < c882e8cc68fb993700dc21fd6e754001e6297934
Status affected
Version 8e8782c71595a5ad29e234ce6b3d2fce787fb07a
Version < 6d2c973926d0612360693bc559be2ffde836151b
Status affected
Version 8e8782c71595a5ad29e234ce6b3d2fce787fb07a
Version < 60ed00d46616a9232e42ea7a3e3c0273d7cf7543
Status affected
Version 8e8782c71595a5ad29e234ce6b3d2fce787fb07a
Version < cb2fc37857693b55909fb77dc2c87cfbc1cdc476
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.16
Status affected
Version 0
Version < 3.16
Status unaffected
Version <= 5.10.*
Version 5.10.266
Status unaffected
Version <= 5.15.*
Version 5.15.217
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/016ef0f6ca4bc9bf0330ac41bd2ea349759643e3
https://git.kernel.org/stable/c/c882e8cc68fb993700dc21fd6e754001e6297934
https://git.kernel.org/stable/c/6d2c973926d0612360693bc559be2ffde836151b
https://git.kernel.org/stable/c/60ed00d46616a9232e42ea7a3e3c0273d7cf7543
https://git.kernel.org/stable/c/cb2fc37857693b55909fb77dc2c87cfbc1cdc476
https://git.kernel.org/stable/c/0f29df3c3d607a9dbc14aed0e45504ced4d2e7ec
https://git.kernel.org/stable/c/38d4947431b2410850409fda016b2ac9f640a4dd
https://git.kernel.org/stable/c/e3e8b02d4773cfc5ad561d2e5505efde36c6927a