CVE-2026-19185
Received Received - Intake

Memory Corruption in Zephyr RTOS I3C Subsystem

Vulnerability report for CVE-2026-19185, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Zephyr Project

Description

The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data pointer and data_len, and neither was passed through K_SYSCALL_MEMORY() before the payload was handed to z_impl_i3c_do_ccc() and on to the controller driver. The verifier also operated on the caller's live structure rather than a snapshot, so validated fields could be changed by a second user thread between the check and the driver's use β€” unlike the sibling z_vrfy_i3c_transfer(), which has always copied its message array first. The defect is only present in CONFIG_USERSPACE builds, where drivers/i3c/i3c_handlers.c is compiled. An unprivileged user-mode thread that has been granted access to the I3C controller device object β€” the ordinary way an application lets a user thread talk to I3C peripherals β€” can issue a direct CCC whose target payload data pointer names an arbitrary kernel address. Controller drivers dereference that pointer directly (for example drivers/i3c/i3c_mcux.c, drivers/i3c/i3c_cdns.c, drivers/i3c/i3c_stm32.c, drivers/i3c/i3c_npcx.c), using rnw to decide direction. A read CCC therefore causes the kernel-mode driver to write bus-received bytes into an attacker-chosen kernel address for an attacker-chosen length, and a write CCC transmits kernel memory out onto the I3C bus. The result is an out-of-bounds kernel write plus a kernel memory disclosure, i.e. escalation from a user-mode thread to supervisor privilege, defeating the isolation CONFIG_USERSPACE is meant to provide. The fix introduces copy_ccc_and_do(), which snapshots the payload, copies the target array into kernel memory with k_usermode_alloc_from_copy() (bounding num_targets to fewer than 32), validates each per-target buffer with K_SYSCALL_MEMORY() according to rnw, and copies the driver-written num_xfer and err fields back to the caller.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-822 The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a syscall verifier flaw in Zephyr RTOS's I3C driver. The verifier for i3c_do_ccc() failed to validate nested CCC buffers, specifically per-target data buffers. This allows an unprivileged user thread with I3C controller access to exploit two attack vectors: issuing a read CCC to write kernel memory or a write CCC to leak kernel memory. The flaw exists only in CONFIG_USERSPACE builds and enables privilege escalation by bypassing user-mode isolation.

Detection Guidance

This vulnerability is specific to Zephyr RTOS systems with CONFIG_USERSPACE enabled and the I3C driver compiled. Detection requires checking if your system runs a vulnerable Zephyr version (3.2.0 to 4.4.2) with CONFIG_USERSPACE and I3C support. Commands: grep 'CONFIG_USERSPACE=y' .config; grep 'CONFIG_I3C=y' .config; git log --oneline --grep='i3c_do_ccc' --all.

Impact Analysis

An attacker with access to an I3C controller device could escalate privileges from a user-mode thread to supervisor level. They could write arbitrary kernel memory or leak sensitive kernel data, compromising system integrity and confidentiality. This defeats the isolation provided by CONFIG_USERSPACE in Zephyr RTOS.

Mitigation Strategies

Apply the official patch from Zephyr's repository (commit 35562f22f40c6d2f31969a31f0a4902e5b067f27). Disable CONFIG_USERSPACE if not required. Restrict access to I3C controller devices to trusted users only. Monitor for unusual I3C bus activity or kernel memory corruption signs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19185. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart