CVE-2026-19569
Received Received - Intake

Heap Overflow in Zephyr RTOS Kernel

Vulnerability report for CVE-2026-19569, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Zephyr Project

Description

dynamic_object_create() in kernel/userspace/userspace.c computed the backing allocation for a dynamically allocated kernel object as obj_size_get(otype) + size, and for thread stack elements as STACK_ELEMENT_DATA_SIZE(size) (a round-up plus fixed overhead), without checking either expression for unsigned wrap-around. A size close to SIZE_MAX makes the computed total wrap to a very small value, so the heap chunk handed out is a few bytes while the object descriptor is still tagged with the full requested type and registered in the kernel object table. The size argument reaches that arithmetic directly from user mode. k_object_alloc_size() is declared __syscall in include/zephyr/sys/kobject.h, its verifier z_vrfy_k_object_alloc_size() in kernel/userspace/userspace_handler.c is a bare pass-through, and z_object_alloc() only range-checks otype β€” nothing bounds size. The stack-element branch is additionally reachable through the k_thread_stack_alloc() syscall via kernel/dynamic.c. Because subsequent kernel-object validation checks only the object's type and initialization state, the undersized handle passes K_SYSCALL_OBJ_INIT()/K_SYSCALL_OBJ_NEVER_INIT(), and the matching init syscall (for example k_mutex_init(), k_sem_init(), or k_thread_create()) then writes a complete object over the truncated allocation. An unprivileged user-mode thread can therefore trigger a supervisor-mode out-of-bounds write into the kernel resource-pool heap, of a size and content it substantially controls, corrupting sys_heap chunk metadata and adjacent kernel objects. Under CONFIG_GEN_PRIV_STACKS the thread-stack branch additionally stores an attacker-influenced wild pointer as a user thread's privileged stack base. The practical result is escape from the CONFIG_USERSPACE sandbox β€” kernel-level code execution or at minimum kernel memory corruption and system compromise. Exploitation requires CONFIG_USERSPACE together with CONFIG_DYNAMIC_OBJECTS (also selected by CONFIG_DYNAMIC_THREAD under userspace), and a calling thread with an assigned resource pool. The fix rejects both overflowing computations and frees the partially built descriptor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 3.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19569 is an integer overflow in the Zephyr RTOS kernel's dynamic object allocation. The function dynamic_object_create() calculates allocation sizes without checking for unsigned wrap-around. A user-provided size near SIZE_MAX causes the computed total to wrap to a small value, leading to undersized heap allocations while the object descriptor retains the full requested type. Subsequent initialization writes a full object over the small buffer, causing out-of-bounds writes into kernel memory.

Detection Guidance

Detecting this vulnerability requires checking for Zephyr RTOS versions between 3.5.0 and 4.4.2 with CONFIG_USERSPACE and CONFIG_DYNAMIC_OBJECTS enabled. Inspect kernel logs for heap corruption or out-of-bounds writes during dynamic object allocation. Use static analysis tools to verify the presence of overflow checks in dynamic_object_create() and related functions.

Impact Analysis

An attacker can trigger out-of-bounds writes into the kernel heap, corrupting memory or adjacent objects. This may lead to kernel crashes, denial of service, or privilege escalation. In some configurations, it can also allow writing a controlled pointer into a privileged stack base, enabling sandbox escape and full kernel-level code execution.

Mitigation Strategies

Upgrade Zephyr RTOS to version 4.5.0 or later where the fix is included. Disable CONFIG_USERSPACE and CONFIG_DYNAMIC_OBJECTS if not required. Apply the patch from commit 85c1c4c21945d9b8fcef03216f1ccb2b27794e3d if upgrading is not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19569. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart