MEDIUM

CVE-2026-52948

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl

While fuzzing with Syzkaller, a persistent `schedule_timeout: wrong
timeout value` warning was observed, accompanied by SMBus controller
state machine corruption.

The I2C_TIMEOUT ioctl accepts a user-provided timeout in multiples of
10 ms. The user argument is checked against INT_MAX, but it is
subsequently multiplied by 10 before being passed to msecs_to_jiffies().

A malicious user can pass a large value (e.g., 429496729) that passes
the `arg > INT_MAX` check but overflows when multiplied by 10. This
results in a truncated 32-bit unsigned value that bypasses the
internal `(int)m < 0` check in `msecs_to_jiffies()`.

The truncated value is then assigned to `client->adapter->timeout`
(a signed 32-bit int), which is reinterpreted as a negative number.
When passed to wait_for_completion_timeout(), this negative value
undergoes sign extension to a 64-bit unsigned long, triggering the
`schedule_timeout` warning and causing premature returns. This leaves
the SMBus state machine in an unrecoverable state, constituting a
local Denial of Service (DoS).

Fix this by bounding the user argument to `INT_MAX / 10`.

[wsa: move the comment as well]

Summary dbcve.org

Integer overflow in Linux kernel's I2C_TIMEOUT ioctl where user-provided timeout value is checked against INT_MAX but then multiplied by 10, causing overflow. The truncated result becomes negative when cast to signed 32-bit int, leading to premature wait_for_completion_timeout() returns and SMBus state machine corruption, constituting local DoS.

Mitigation

Apply the kernel patch to bound user argument to INT_MAX / 10 before multiplication, preventing the overflow that leads to negative timeout values.

Patch Commit

Weakness (CWE)

CWE-190 Integer Overflow

EPSS Score

0.13%
Probability of exploitation in next 30 days
3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE