CVE-2026-19184
Received Received - Intake

Buffer Overflow in NXP GAU ADC Driver

Vulnerability report for CVE-2026-19184, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Zephyr Project

Description

The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results_length and used it in mcux_gau_adc_read_samples() as the number of uint16_t slots available. Because each conversion result occupies sizeof(uint16_t) bytes, a buffer that was accepted as "large enough" could be written with up to twice its size in bytes, so every sample past the buffer's midpoint was written out of bounds. adc_read() and adc_read_async() are Zephyr system calls. The syscall verifier in drivers/adc/adc_handlers.c only confirms that the caller owns buffer_size writable bytes (K_SYSCALL_MEMORY_WRITE); deciding whether that size is sufficient for the requested channels and extra_samplings is delegated entirely to the driver. On a build with CONFIG_USERSPACE=y, a user-mode thread that has been granted the ADC device object could therefore submit a deliberately half-sized buffer and cause the driver's work-queue handler β€” which runs in supervisor mode, outside the caller's MPU restrictions β€” to write ADC conversion results past the end of that buffer, at an address and for a length of the caller's choosing. The overrun is bounded by the requested sequence: with sequence->options->extra_samplings set, the sampling loop walks the buffer pointer forward across every sampling, so the total overrun can reach the full size of the supplied buffer (kilobytes for a large extra_samplings). The written words are 16-bit ADC conversion results, so the content is only partially attacker-influenced (via the selected analog input, gain and resolution), but the destination and length are fully controlled β€” sufficient for kernel memory corruption, a crash, or a userspace-to-kernel privilege escalation. Builds without CONFIG_USERSPACE, or on SoCs other than NXP RW61x with the GAU ADC node enabled, are not exposed to the privilege boundary; there the same defect only causes a silent overflow when the application itself passes an undersized buffer. The fix replaces the ad-hoc check with the shared adc_sequence_validate_buffer() helper (validating against num_channels * sizeof(uint16_t)), stores buffer_size / sizeof(uint16_t) in results_length, and corrects the loop bound to a post-decrement so exactly the available number of slots may be written.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nxp gau_adc *
zephyrproject zephyr *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow issue in the NXP GAU ADC driver for Zephyr RTOS. The driver incorrectly validated a buffer size in bytes against the number of active channels (a sample count), allowing undersized buffers to pass checks. This led to out-of-bounds writes when the driver stored the byte count as a slot count for 16-bit samples, potentially corrupting memory or enabling privilege escalation.

Detection Guidance

This vulnerability is specific to the NXP GAU ADC driver in Zephyr RTOS and requires code inspection or runtime monitoring. No direct network detection commands exist. Check Zephyr RTOS versions between 3.7.0 and 4.4.2 with CONFIG_USERSPACE enabled. Review drivers/adc/adc_mcux_gau_adc.c for the described buffer validation flaw.

Impact Analysis

On systems with CONFIG_USERSPACE enabled, a user-mode thread with ADC device access could exploit this to corrupt kernel memory, crash the system, or escalate privileges. Without CONFIG_USERSPACE, it causes silent buffer overflows when applications pass undersized buffers.

Mitigation Strategies

Apply the official patch from Zephyr RTOS commit 82b11958065aa85f8644ddc318ff4a328d1443c8. Disable CONFIG_USERSPACE if not required. Update to Zephyr versions 4.4.3 or later. For systems unable to patch immediately, restrict ADC device access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19184. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart