CVE-2026-52948 Details
Description
In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl While fuzzing with Syzkaller, a persistent `schedule_timeout: wrong timeout value` warning was observed, accompanied by SMBus controller state machine corruption. The I2C_TIMEOUT ioctl accepts a user-provided timeout in multiples of 10 ms. The user argument is checked against INT_MAX, but it is subsequently multiplied by 10 before being passed to msecs_to_jiffies(). A malicious user can pass a large value (e.g., 429496729) that passes the `arg > INT_MAX` check but overflows when multiplied by 10. This results in a truncated 32-bit unsigned value that bypasses the internal `(int)m < 0` check in `msecs_to_jiffies()`. The truncated value is then assigned to `client->adapter->timeout` (a signed 32-bit int), which is reinterpreted as a negative number. When passed to wait_for_completion_timeout(), this negative value undergoes sign extension to a 64-bit unsigned long, triggering the `schedule_timeout` warning and causing premature returns. This leaves the SMBus state machine in an unrecoverable state, constituting a local Denial of Service (DoS). Fix this by bounding the user argument to `INT_MAX / 10`. [wsa: move the comment as well]
A vulnerability in the Linux kernel's I2C subsystem allows for the manipulation of timeout values through the I2C_TIMEOUT ioctl, leading to a local denial-of-service condition. The issue arises because the ioctl accepts user-provided timeout values in multiples of 10 ms. Although the input is initially validated against INT_MAX, it is later multiplied by 10 before being converted to jiffies. This creates an opportunity for exploitation: a malicious user can send a large value that passes the initial check but overflows when multiplied, resulting in a truncated value that bypasses further validation. The corrupted value is then interpreted as negative, causing improper handling of the SMBus state machine and triggering a 'schedule_timeout: wrong timeout value' warning. This corruption leaves the state machine in an unrecoverable condition, causing a local denial-of-service situation.
Users can apply the available patch to address this vulnerability. The patch is included in the official Linux kernel repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0b88ecfbc9dc33b4db8836c37b50cf174e6c0691 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4576621dc6577f21a032acfd16c3ad61907a5ea7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/617eb7c0961a8dfcfc811844a6396e406b2923ea | kernel.org | Patch |
| https://git.kernel.org/stable/c/943e318eedbeaeea08ece3f5dd44c982f4ed2ef5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/aa6ef734016912653a909477fb30aeb66c98b3a2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e9ffd5f5050fbb199d270a85614cd27ebed6fbac | kernel.org | Patch |
| https://git.kernel.org/stable/c/ff02add34ffd03449b8115904ebe2ec4fed022d4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ffbcf31f032eb454ebfd29309f51366fe57f4ac4 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.29.1, < 5.10.259 >= 5.11, < 5.15.210 >= 5.16, < 6.1.176 >= 6.2, < 6.6.143 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 2.6.29 - 2.6.29 rc7 2.6.29 rc8 7.1 rc1 7.1 rc2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jun 29, 2026 | CVE Modified | kernel.org |
| Jun 24, 2026 | New CVE Received | kernel.org |