Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72142— i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于SMBus块读取字节计数为0时原子轮询路径处理不当,返回错误时未发送NACK+STOP,可能导致I2C总线锁死。

AI Predicted 5.3 Difficulty: Moderate EPSS 0.21% · P11

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 8e8782c71595a5ad29e234ce6b3d2fce787fb07a< 0f29df3c3d607a9dbc14aed0e45504ced4d2e7ec affected
8e8782c71595a5ad29e234ce6b3d2fce787fb07a< 38d4947431b2410850409fda016b2ac9f640a4dd affected
8e8782c71595a5ad29e234ce6b3d2fce787fb07a< e3e8b02d4773cfc5ad561d2e5505efde36c6927a affected
8e8782c71595a5ad29e234ce6b3d2fce787fb07a< 016ef0f6ca4bc9bf0330ac41bd2ea349759643e3 affected
8e8782c71595a5ad29e234ce6b3d2fce787fb07a< c882e8cc68fb993700dc21fd6e754001e6297934 affected
8e8782c71595a5ad29e234ce6b3d2fce787fb07a< 6d2c973926d0612360693bc559be2ffde836151b affected
8e8782c71595a5ad29e234ce6b3d2fce787fb07a< 60ed00d46616a9232e42ea7a3e3c0273d7cf7543 affected
8e8782c71595a5ad29e234ce6b3d2fce787fb07a< cb2fc37857693b55909fb77dc2c87cfbc1cdc476 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72142

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
i2c: imx: fix locked bus on SMBus block-read of 0 (atomic)
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) SMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic (polling) path rejects it as -EPROTO. Worse, it returns without a NACK+STOP: the next receive cycle has already started, so the target keeps holding SDA and the bus stays stuck until a power cycle for this i2c controller. Reading I2DR to obtain the count likewise arms the next byte on the count > I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly and left the bus held. Handle both: NACK the in-flight dummy byte (TXAK) and extend msgs->len so the existing last-byte handling emits STOP; the dummy byte is discarded. A count of 0 is a valid empty block read; a count above I2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus has been released. The interrupt-driven path has the same flaw from a later commit and is fixed separately, as it carries a different Fixes: tag and stable range.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于SMBus块读取字节计数为0时原子轮询路径处理不当,返回错误时未发送NACK+STOP,可能导致I2C总线锁死。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 8e8782c71595a5ad29e234ce6b3d2fce787fb07a ~ 0f29df3c3d607a9dbc14aed0e45504ced4d2e7ec -
Linux Linux 3.16 -

II. Public POCs for CVE-2026-72142

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72142

登录查看更多情报信息。

Patches & Fixes for CVE-2026-72142 (6)

Other References for CVE-2026-72142 (1)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-74475 10.0 CRITICAL vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74280 10.0 CRITICAL crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-74279 10.0 CRITICAL crypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-72408 10.0 CRITICAL geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-74309 10.0 CRITICAL vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-72421 10.0 CRITICAL ipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-72407 10.0 CRITICAL geneve: validate inner network offset in geneve_gro_complete()
CVE-2026-72493 9.9 CRITICAL net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-72201 9.8 CRITICAL ntfs: validate index entries on reading
CVE-2026-72065 9.8 CRITICAL net: mana: Validate the packet length reported by the NIC
CVE-2026-72064 9.8 CRITICAL net: mana: Sync page pool RX frags for CPU
CVE-2026-74480 9.8 CRITICAL net: bridge: stop fast-leave after deleting a port group
CVE-2026-72191 9.8 CRITICAL ntfs3: validate split-point offset in indx_insert_into_buffer
CVE-2026-72192 9.8 CRITICAL ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head
CVE-2026-74478 9.8 CRITICAL um: vector: fix use-after-free in vector_mmsg_rx()
CVE-2026-72194 9.8 CRITICAL fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
CVE-2026-74269 9.8 CRITICAL bnxt: fix head underflow on XDP head-grow
CVE-2026-72209 9.8 CRITICAL ntfs: validate attribute values on lookup
CVE-2026-72211 9.8 CRITICAL ntfs: grow index root value before reparent header update
CVE-2026-72210 9.8 CRITICAL ntfs: fix off-by-one in mapping pairs decoding bounds checks

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72142

No comments yet


Leave a comment