CVE-2026-18413
Received Received - Intake

Buffer Overflow in NXP MCUX LPADC Driver

Vulnerability report for CVE-2026-18413, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Zephyr Project

Description

The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The NXP MCUX LPADC driver did not honour that contract. mcux_lpadc_start_read() in drivers/adc/adc_mcux_lpadc.c performed no buffer-size check at all before assigning data->buffer = sequence->buffer. Each completed conversion then stores one 16-bit sample per enabled channel per sampling round through an unbounded *data->buffer++: in mcux_lpadc_isr() for interrupt-driven builds, and in mcux_lpadc_dma_callback() for DMA-driven builds on releases that have the DMA path. A sequence selecting two channels with a two-byte buffer, for example, has its second sample written past the end of the buffer. On a build with CONFIG_USERSPACE, adc_read() and adc_read_async() are system calls. The handler in drivers/adc/adc_handlers.c copies the sequence in from user memory, verifies only that [buffer, buffer + buffer_size) is writable by the calling thread, and rejects a user-supplied options->callback; it deliberately leaves the size arithmetic to the driver. A user-mode thread that has been granted access to an LPADC device object therefore fully controls channels, buffer, buffer_size and options->extra_samplings, and can request far more samples than its buffer can hold: up to channels * 65536 samples into a two-byte buffer, since the sample pointer is only rewound on a repeat sampling, never on the extra samplings of a sequence. The resulting stores are performed by the driver in kernel mode (in the ADC interrupt handler or the DMA completion callback), where the MPU does not restrict the thread's memory domain, so the write walks linearly out of the user partition and into adjacent memory such as other partitions, kernel data or thread stacks. The impact is kernel-memory corruption of attacker-chosen length at an attacker-chosen offset, a plausible privilege-escalation and denial-of-service primitive from an unprivileged user-mode thread. Builds without CONFIG_USERSPACE are affected only as a caller-side robustness defect, since the application itself supplies the buffer. The fix calls the new shared helper adc_sequence_validate_buffer() in drivers/adc/adc_common.c from mcux_lpadc_start_read(). The helper computes active_channels sizeof(uint16_t) (1 + extra_samplings) and returns -ENOMEM before any sampling is started.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nxp mcux_lpadc to 3.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a buffer overflow in the NXP MCUX LPADC driver for the Zephyr RTOS. The driver fails to check if the provided buffer is large enough to hold the sampled data before writing to it. When a user requests more samples than the buffer can hold, the driver writes beyond the buffer's limit, corrupting adjacent memory in kernel space. This can lead to privilege escalation or denial of service from an unprivileged user thread.

Detection Guidance

This vulnerability is specific to the NXP MCUX LPADC driver in Zephyr OS and requires code inspection or runtime monitoring. No direct network detection commands exist. Check for kernel memory corruption symptoms like crashes or unexpected behavior in ADC operations. Review driver code for missing buffer-size checks in mcux_lpadc_start_read().

Impact Analysis

If exploited, this vulnerability allows an attacker to corrupt kernel memory, potentially leading to privilege escalation or system crashes. On systems with CONFIG_USERSPACE enabled, an unprivileged user can trigger this by requesting excessive samples. Without CONFIG_USERSPACE, the impact is limited to application crashes due to buffer overflow.

Compliance Impact

This vulnerability could lead to kernel-memory corruption, potentially allowing privilege escalation and denial-of-service attacks from unprivileged user-mode threads. Such impacts may violate compliance requirements under GDPR (e.g., integrity of personal data processing) and HIPAA (e.g., unauthorized access to protected health information systems).

Mitigation Strategies

Apply the official patch from Zephyr Project that adds buffer-size validation via adc_sequence_validate_buffer(). Disable CONFIG_USERSPACE if enabled to reduce attack surface. Restrict access to LPADC devices to trusted user-mode threads only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18413. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart