CVE-2026-97515

In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845 On NPCM845, when a target on the I3C bus gets stuck holding SDA low, the controller reports a false Master Request (MR) in-band interrupt event. The driver handles this by emitting a STOP condition to restore the bus. However, the hardware quirk SVC_I3C_QUIRK_FALSE_SLVSTART indicates that emitting a STOP condition may spuriously set the SLVSTART interrupt status bit. In the Master Request case, this creates a feedback loop: the STOP triggers a new SLVSTART event, the IRQ handler fires again, the controller still reports an MR type, another STOP is emitted, and the cycle repeats indefinitely, resulting in an IRQ storm that can lock up the CPU. Clear the SLVSTART status bit explicitly after emitting the STOP in the Master Request IBI handler when the SVC_I3C_QUIRK_FALSE_SLVSTART quirk is set. This breaks the feedback loop without affecting normal SLVSTART processing, which is already guarded in the top-level IRQ handler by checking that MSTATUS is in SLVREQ state.

Package Linux Kernel
Published 2026-09-24
Last modified 2026-09-28
Patch available
Yes

Affected versions

Linux kernel versions 5.15.185, 6.1.141, 6.6.93, 6.12.31, 6.14.9, 6.15 and later are affected. Fixed in 6.18.53, 7.2 and their respective stable series.

Affected from
≥ 5.15.185 ≥ 6.1.141 ≥ 6.6.93 ≥ 6.12.31 ≥ 6.14.9 ≥ 6.15
Fixed in
✓ 6.18.53 6.18.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-97515?

    CVE-2026-97515 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.15.185 onward and has been patched in 6.18.53 and 7.2. CVE-2026-97515 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-97515?

    Yes. CVE-2026-97515 has been patched. Fixed versions include 6.18.53 and 7.2. If you are running Linux kernel 5.15.185 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-97515 actively exploited?

    No. CVE-2026-97515 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.