CVE-2026-16513
Received Received - Intake

Memory Corruption in Zephyr RTIO Subsystem

Vulnerability report for CVE-2026-16513, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Zephyr Project

Description

The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On the first loop iteration it executed *handle = sqe, storing the kernel address of the newly acquired submission-queue entry through a pointer taken verbatim from user mode, with no K_SYSCALL_MEMORY_WRITE check in front of it. Any user-mode thread that has been granted a struct rtio kernel object can invoke the syscall with an arbitrary address in handle. That is the ordinary way an unprivileged thread uses the RTIO API, for example via sensor_read_async_mempool() or the async ADC helpers, which call rtio_sqe_copy_in_get_handles() internally. The store happens in supervisor mode before any submission-entry validation, so it fires regardless of whether the SQE contents are subsequently rejected. Only builds with CONFIG_USERSPACE and CONFIG_RTIO are affected; without CONFIG_USERSPACE the verifier is not compiled and the caller is already privileged. The write address is fully attacker-chosen and the written value is a pointer into the caller's own RTIO ring, whose contents the caller controls (the following *sqe = sqes[i] copies an attacker-supplied struct rtio_sqe into that slot). This yields a write-what-where primitive placing a pointer to attacker-controlled data at any kernel address, sufficient to corrupt kernel function pointers, thread structures, or memory-domain partition tables, and thus to escalate from user mode to kernel mode, defeating the isolation boundary CONFIG_USERSPACE is meant to enforce. At minimum it is a reliable kernel memory-corruption and crash primitive. The reporter reproduced the write on qemu_x86: a K_USER thread changed a supervisor global from NULL to a live kernel SQE pointer. The fix adds K_SYSCALL_MEMORY_WRITE(handle, sizeof(*handle)) (guarded by the existing optional-NULL semantics) before the loop, so the destination must lie in the calling thread's writable memory domain or the thread is terminated by K_OOPS. The neighbouring verifier z_vrfy_rtio_cqe_get_mempool_buffer(), which checked its buff/buff_len out-parameters only for read although the implementation writes through them, was hardened separately by bea93400138 ("rtio: syscalls: validate output params as writable"); that residual was materially weaker, since a read check still confines the target to the caller's own memory domain.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr to 4.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory corruption issue in the Zephyr RTOS RTIO subsystem. It allows an attacker with access to a struct rtio kernel object to write a kernel address into a user-controlled memory location. The flaw occurs because the verifier function z_vrfy_rtio_sqe_copy_in_get_handles() does not validate the handle out-parameter before writing to it. This creates a write-what-where primitive where attackers can corrupt kernel memory, potentially escalating privileges from user mode to kernel mode.

Detection Guidance

This vulnerability affects systems running Zephyr RTOS with CONFIG_USERSPACE and CONFIG_RTIO enabled. Detection requires checking kernel configuration and syscall usage. Examine system logs for crashes or memory corruption during RTIO operations. Monitor for unexpected kernel memory writes or pointer manipulations in RTIO-related syscalls.

Impact Analysis

This vulnerability allows an attacker to corrupt kernel memory, which could lead to system crashes or privilege escalation. An attacker could modify kernel function pointers or memory structures to gain full control over the system. The impact is limited to systems with CONFIG_USERSPACE and CONFIG_RTIO enabled, as these configurations are required for the vulnerable code path.

Compliance Impact

This vulnerability allows an attacker to write arbitrary kernel memory, potentially bypassing security boundaries enforced by CONFIG_USERSPACE. This could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information.

Mitigation Strategies

Apply the vendor patch adding K_SYSCALL_MEMORY_WRITE(handle, sizeof(*handle)) before the loop in z_vrfy_rtio_sqe_copy_in_get_handles(). Disable CONFIG_USERSPACE or CONFIG_RTIO if not required. Restrict access to RTIO syscalls for unprivileged users. Monitor for suspicious activity in RTIO-related processes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16513. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart