CVE-2026-18418
Received Received - Intake

Stack-based Buffer Overread in Zephyr RTOS zbus Proxy Agent

Vulnerability report for CVE-2026-18418, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

The zbus proxy agent IPC backend in subsys/zbus/proxy_agent/zbus_proxy_agent_ipc.c logged the channel name of a rejected inter-domain frame with a plain %s conversion. The frame type struct zbus_proxy_msg carries a fixed-size channel_name[] array as its last member, and nothing in the transport guarantees the array is NUL-terminated. The only code that verifies termination is zbus_proxy_agent_receive_cb() in subsys/zbus/proxy_agent/zbus_proxy_agent.c, which rejects the frame in precisely those cases β€” so the warning printed a non-terminated buffer exactly on the error paths where the name had been found invalid (or, for an invalid message_size, had not been inspected at all). Any peer domain able to place a frame of sizeof(struct zbus_proxy_msg) bytes on the bound ipc_service endpoint can trigger it, by sending a frame with an out-of-range message_size or with channel_name[] containing no NUL byte. Reaching the code requires CONFIG_ZBUS_PROXY_AGENT_IPC and logging built at warning level or above (the default), and requires control over the firmware of the peer domain β€” typically a second core on the same SoC. The resulting strlen() inside the log packager walks past the end of the frame object until it finds a zero byte. With the icmsg backend the frame lives in a stack buffer of the IPC work-queue thread, so bytes of that thread's stack are rendered into the log message; with the rpmsg backends the scan continues through the shared vring memory. Impact is bounded to disclosure of a small amount of adjacent memory into the receiving domain's log sink, plus a possible fatal fault if the scan leaves a mapped region; the log packager's own -ENOSPC bound prevents the overrun from becoming a write. The fix bounds the conversion with %.*s and MIN(msg->channel_name_len, sizeof(msg->channel_name)).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 4.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read in the Zephyr RTOS zbus proxy agent IPC backend. It occurs when logging a rejected inter-domain frame's channel name. The channel name in the struct zbus_proxy_msg may not be NUL-terminated because the transport does not guarantee it. An attacker with control over a peer domain's firmware can send a malformed frame triggering the out-of-bounds read during logging.

Detection Guidance

This vulnerability requires CONFIG_ZBUS_PROXY_AGENT_IPC enabled and logging at warning level or above. Check Zephyr RTOS configuration for zbus proxy agent IPC support and review logs for out-of-bounds read warnings during frame processing.

Impact Analysis

The impact is limited to disclosure of a small amount of adjacent memory in the receiver domain's log sink. It does not escalate to a write due to bounds checks in the logging system. A fatal fault could occur if the scan leaves a mapped region, but this is prevented by the log packager's -ENOSPC bound.

Compliance Impact

This vulnerability primarily impacts confidentiality by potentially exposing adjacent memory in logs. For GDPR, it could lead to unintended data exposure if logs contain personal data. For HIPAA, it may risk disclosure of protected health information if such data is logged. However, the impact is limited to read-only memory exposure and does not involve data modification or unauthorized access.

Mitigation Strategies

Apply the official patch from Zephyr RTOS commit fc065f79a568a6c6cc14b89795bd60e5eabd6f02 which modifies logging to use %.*s with explicit length bounds. Alternatively, disable CONFIG_ZBUS_PROXY_AGENT_IPC if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18418. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart