CVE-2026-19737
Received Received - Intake

Null Pointer Dereference in Espressif I2S Driver

Vulnerability report for CVE-2026-19737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

i2s_esp32_trigger_check() in drivers/i2s/i2s_esp32.c validates the requested direction only for I2S_DIR_BOTH. The I2S_DIR_RX and I2S_DIR_TX branches read dev_cfg->rx.data->configured / dev_cfg->tx.data->configured without first checking the stream pointers. The device instantiation macro I2S_ESP32_STREAM_INIT() sets both .conf and .data to NULL for a direction the devicetree does not describe, so on an instance that wires only one direction β€” the normal shape for audio output or a worldsemi,ws2812-i2s LED strip β€” the other direction dereferences a NULL pointer instead of returning an error. i2s_trigger() is a Zephyr syscall, and z_vrfy_i2s_trigger() in drivers/i2s/i2s_handlers.c validates only the device object and the presence of the trigger API pointer; the dir argument is passed to the driver unvalidated. On a build with CONFIG_USERSPACE enabled, a user-mode thread that has been granted the I2S device can issue a single i2s_trigger() call naming the unwired direction and cause a load from address 0 in kernel mode. Among the Espressif parts that carry this driver, userspace is available in-tree only on RISC-V SoCs with CONFIG_RISCV_PMP, and v4.4.0 is the first release where that is buildable: the ESP32-C6 HPCORE selects RISCV_PMP when it is not built for MCUboot. ESP32-C5 in v4.4.x carries the same PMP-region and userspace linker support but does not select RISCV_PMP by default. Espressif Xtensa targets do not support Zephyr userspace, and in a non-userspace build the bad direction can only come from in-kernel application code. The impact is limited to availability: the access is a read at offset 0 of the missing stream structure, so there is no attacker-controlled offset, no write primitive and no information disclosure. With the default fatal-error handler the resulting exception halts the system, giving an unprivileged user-mode thread a system-wide denial of service. The fix adds the same pointer check the I2S_DIR_BOTH branch already performed and returns -ENOSYS for a direction the instance does not implement; the driver's other entry points (i2s_esp32_config_check(), i2s_esp32_config_get(), i2s_esp32_read(), i2s_esp32_write()) already guarded the pointers, and a static audit found no equivalent unguarded path. The driver defect is older than the affected range. The unguarded dereference is present from v4.2.0 (reached through i2s_esp32_trigger_stream(), whose if (stream) guard tests the address of a struct member and is never false) and takes its present i2s_esp32_trigger_check() form in v4.3.0. No in-tree Espressif configuration before v4.4.0 can run a user-mode thread, so in v4.2.x and v4.3.x the direction argument can only come from trusted kernel code. Those releases carry the bug but are not listed as affected; the fix has also been merged to v4.3-branch as hardening.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 4.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19737 is a NULL pointer dereference vulnerability in the ESP32 I2S driver of the Zephyr RTOS. The issue occurs in the i2s_esp32_trigger_check() function where the driver fails to validate the requested direction (RX or TX) before accessing device configuration structures. When an unsupported direction is triggered, the driver attempts to read from a NULL pointer, leading to a kernel-mode crash.

Detection Guidance

This vulnerability is specific to Zephyr RTOS systems running the ESP32 I2S driver. Detection requires checking the Zephyr version and I2S driver configuration. For systems with CONFIG_USERSPACE enabled on RISC-V SoCs like ESP32-C6, verify if the driver is compiled with the affected code path. No direct network detection commands exist; inspect Zephyr build logs for I2S driver usage and version.

Impact Analysis

The vulnerability allows an unprivileged user-mode thread with access to the I2S device to trigger a denial-of-service (DoS) by issuing an i2s_trigger() call with an invalid direction. This results in a system halt due to the fatal-error handler. The impact is limited to availability, as the NULL pointer dereference only reads from address 0 without enabling further exploitation like information disclosure or privilege escalation.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it only impacts system availability through a denial-of-service condition. There is no evidence of data disclosure or unauthorized access, which are key concerns for these regulations.

Mitigation Strategies

Apply the official patch from Zephyr v4.5.0 or backport the fix to v4.4.x. Disable CONFIG_USERSPACE if not required, especially on RISC-V SoCs. Avoid granting unprivileged user-mode threads access to the I2S device. Monitor Zephyr project advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19737. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart