---
id: CVE-2026-93202
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  i3c: master: Fix recursive locking during device registration

  i3c_master_register_new_i3c_devs() registers newly discovered devices
  while holding i3c_bus_normaluse_loc…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  i3c: master: Fix recursive locking during device registration

  i3c_master_register_new_i3c_devs() registers newly discovered devices
  while holding i3c_bus_normaluse_loc…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 <
    b25232f66e8cd653d0c6bfdbe534e62a2f9d6a1b
  - >-
    Linux >= 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 <
    9dc73c51ed3ee965c3ddb0ac31cf5c3eea68fa0c
  - >-
    Linux >= 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 <
    456f832e5fc26fbfd3b8200fd4553eee520cc377
  - Linux 5.0
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:18:16.510'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93202'
references:
  - url: 'https://git.kernel.org/stable/c/456f832e5fc26fbfd3b8200fd4553eee520cc377'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9dc73c51ed3ee965c3ddb0ac31cf5c3eea68fa0c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b25232f66e8cd653d0c6bfdbe534e62a2f9d6a1b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.720Z'
epss: 0.00154
epssPercentile: 0.04982
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

i3c: master: Fix recursive locking during device registration

i3c_master_register_new_i3c_devs() registers newly discovered devices
while holding i3c_bus_normaluse_lock(), a down_read().  device_register()
can immediately probe the device, and probe callbacks typically invoke
I3C helpers that take i3c_bus_normaluse_lock() again, leading to a
recursive acquisition of the same rwsem.  rwsems do not support recursive
read locking and can deadlock when a writer is waiting.  See the
"Recursive read locks" section of Documentation/locking/lockdep-design.rst.

For example, with Intel LPSS I3C, LOCKDEP generates a WARNING like:
  # echo intel-lpss-i3c.0 > /sys/bus/platform/drivers/mipi-i3c-hci/unbind
  # echo intel-lpss-i3c.0 > /sys/bus/platform/drivers/mipi-i3c-hci/bind
  WARNING: possible recursive locking detected
  kworker/5:1/94 is trying to acquire lock:
  ffff88811c810d78 (&i3cbus->lock){++++}-{4:4}, at: i3c_device_match_id+0x45/0x370
  but task is already holding lock:
  ffff88811c810d78 (&i3cbus->lock){++++}-{4:4}, at: i3c_master_reg_work_fn+0x21/0x5f0

Fix this by separating device creation from device registration.
Populate desc->dev under the maintenance lock, collect the devices that
still need registration into a local list, then release the lock before
calling device_register().  Finally retake the lock and clean up any
devices that failed to register.

Use the maintenance lock rather than the normal-use lock while adding
device objects.  A write-side maintenance lock prevents readers from
observing a partially initialized desc->dev during initial device
population, or desc->dev disappearing if registration fails.

The local list requires a list node, so add a list node member to struct
i3c_device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
