CVE-2026-17053
Received Received - Intake

Memory Corruption in Zephyr SMBus Driver API

Vulnerability report for CVE-2026-17053, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Zephyr Project

Description

The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded the caller-supplied struct smbus_callback *cb pointer into kernel-mode driver code without any K_SYSCALL_MEMORY_READ/K_SYSCALL_MEMORY_WRITE validation. A companion change in 2023 had already removed the matching smbus_smbalert_set_cb() / smbus_host_notify_set_cb() syscalls for this reason, but the two removal syscalls were left exposed. On a build with CONFIG_USERSPACE=y, CONFIG_SMBUS=y and a driver implementing the callback operations (drivers/smbus/intel_pch_smbus.c with CONFIG_SMBUS_INTEL_PCH_SMBALERT/CONFIG_SMBUS_INTEL_PCH_HOST_NOTIFY, or drivers/smbus/smbus_stm32.c with CONFIG_SMBUS_STM32_SMBALERT), any user-mode thread that has been granted the SMBus device object can invoke these syscalls with an arbitrary pointer. The value reaches smbus_callback_remove() in drivers/smbus/smbus_utils.h, which uses it as a node identity against the kernel's sys_slist_t of registered callbacks. The consequence is that an unprivileged thread can unregister an SMBALERT or Host Notify callback that a supervisor-mode component registered, silently disabling alert handling for the rest of the system; because Zephyr images have fixed symbol addresses and the syscall returns 0 on a hit versus -ENOENT on a miss, the target address is both derivable and searchable. In builds with CONFIG_ASSERT=y the __ASSERT(callback->handler, ...) check additionally dereferences the caller-supplied address in supervisor mode, so a bogus pointer raises a kernel-mode fault and a fatal system error, and the fault/no-fault outcome discloses which addresses are mapped. The fix removes both syscall entry points, demoting the two functions to ordinary static inline calls so that callback list manipulation is available only to supervisor-mode code. There is no impact on builds without CONFIG_USERSPACE, and no impact on configurations that do not enable an SMBus driver with SMBALERT or Host Notify support.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zephyr_project zephyr *
zephyrproject zephyr to 2023 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves two syscalls in the Zephyr RTOS SMBus driver, smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb(), which allowed userspace applications to pass unvalidated callback pointers to kernel mode. These syscalls only checked the device object but not the callback pointer, enabling malicious applications to manipulate kernel callback lists. The issue required specific build configurations with CONFIG_USERSPACE=y and CONFIG_SMBUS=y.

Detection Guidance

This vulnerability is specific to Zephyr RTOS builds with CONFIG_USERSPACE=y, CONFIG_SMBUS=y, and enabled SMBus drivers. Detection requires checking Zephyr configuration and kernel symbols. Use grep to search for CONFIG_USERSPACE and CONFIG_SMBUS in your build config. Check for exposed syscalls by examining kernel symbols for smbus_smbalert_remove_cb and smbus_host_notify_remove_cb. If these symbols are present and marked as syscalls, the system is vulnerable.

Impact Analysis

An unprivileged user thread with SMBus device access could unregister callbacks registered by supervisor code, disabling SMBALERT or Host Notify processing. In builds with CONFIG_ASSERT=y, a bogus pointer could cause a kernel fault, revealing memory layout. The impact is limited to systems with CONFIG_USERSPACE=y, CONFIG_SMBUS=y, and specific SMBus drivers enabled.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to a privilege escalation in the Zephyr RTOS SMBus driver. Compliance impacts would depend on system-specific usage of the affected components, but the vulnerability itself is unrelated to data protection or privacy requirements.

Mitigation Strategies

Apply the official Zephyr patch by updating to a version that removes the exposed syscalls. Rebuild your Zephyr image without CONFIG_USERSPACE or without SMBus drivers if not required. If immediate patching is not possible, disable CONFIG_USERSPACE or the affected SMBus drivers in your build configuration to remove the vulnerable syscall paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17053. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart