CVE-2026-19669
Received Received - Intake

Buffer Overflow in Zephyr RTOS Fuel Gauge Syscall Handlers

Vulnerability report for CVE-2026-19669, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_props[len], sized directly by the caller-supplied len argument. len is an unvalidated size_t taken straight from the syscall ABI, and the VLAs were allocated before any check at all β€” including before the K_SYSCALL_DRIVER_FUEL_GAUGE() object-permission check. The subsequent k_usermode_from_copy() calls validated only that the user source buffer was readable; the kernel destination was never bounds-checked, since it was sized by the same attacker-chosen len. Any thread running in user mode with CONFIG_USERSPACE enabled can invoke fuel_gauge_get_props() or fuel_gauge_set_props() with a large len. This first displaces the supervisor stack pointer by an arbitrary attacker-chosen amount β€” Zephyr does not build with stack-clash probing, so the displacement itself does not fault, and the nested calls made by the verifier then write frames below the privileged stack. If the caller has been granted access to a fuel-gauge device object, the memcpy inside k_usermode_from_copy() additionally writes len * sizeof(union fuel_gauge_prop_val) bytes of fully attacker-controlled data starting well below the stack base. CONFIG_PRIVILEGED_STACK_SIZE defaults to 1024 bytes, so a len of roughly 170 already exhausts it. The result is an out-of-bounds write in supervisor mode with attacker-controlled length and, on the permitted path, attacker-controlled content β€” a break out of the user-mode sandbox into kernel memory, leading to kernel code execution or a system crash. A stack guard region does not contain it, because the copy begins below the guard and walks upward, corrupting unprotected memory before the guard is reached. The fix removes the kernel-side copies entirely and validates the caller's arrays in place with K_SYSCALL_MEMORY_ARRAY_READ() / K_SYSCALL_MEMORY_ARRAY_WRITE(), which also handle the len * size multiplication overflow; this is safe because neither fuel_gauge_prop_t nor union fuel_gauge_prop_val contains embedded pointers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 3.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Zephyr RTOS involves two syscall functions that declare variable-length arrays sized by an unvalidated user-supplied length. The arrays are allocated before any security checks, allowing an attacker to displace the kernel stack pointer and write attacker-controlled data below the stack base. This leads to out-of-bounds writes in supervisor mode, enabling kernel memory corruption or code execution.

Detection Guidance

This vulnerability affects Zephyr RTOS versions 3.4.0 through 4.4.2. To detect it, check your Zephyr RTOS version using git commands like 'git log --oneline' or 'west list'. If your version falls within the affected range, the system is potentially vulnerable. No specific commands are provided for detection beyond version checks.

Impact Analysis

An attacker with user-mode access and CONFIG_USERSPACE enabled could exploit this to crash the system or execute arbitrary kernel code. The default stack size of 1024 bytes can be exhausted with a length of around 170, causing memory corruption before stack guards are reached.

Compliance Impact

This vulnerability could lead to unauthorized kernel memory access or code execution, potentially compromising system integrity and data confidentiality. For GDPR, it may violate principles of data protection and security. For HIPAA, it could risk unauthorized access to protected health information by allowing attackers to bypass user-mode restrictions.

Mitigation Strategies

Apply the official patch from the Zephyr project by updating to a version beyond 4.4.2 or applying the commit 0d65ce46dda0626164503c50f37e6e1f59d310a9. Disable CONFIG_USERSPACE if not required. Monitor for unusual kernel crashes or stack overflow errors in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19669. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart