PT-2026-103906 · Zephyrproject · Zephyr

CVE-2026-17053

·

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v3.1

4.4

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The SMBus driver API exposed smbus smbalert remove cb() and smbus host notify remove cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus handlers.c validated only the dev argument with K SYSCALL OBJ(dev, K OBJ DRIVER SMBUS) and forwarded the caller-supplied struct smbus callback *cb pointer into kernel-mode driver code without any K SYSCALL MEMORY READ/K SYSCALL MEMORY WRITE validation. A companion change in 2023 had already removed the matching smbus smbalert set cb() / smbus host notify set cb() syscalls for this reason, but the two removal syscalls were left exposed.
On a build with CONFIG USERSPACE=y, CONFIG SMBUS=y and a driver implementing the callback operations (drivers/smbus/intel pch smbus.c with CONFIG SMBUS INTEL PCH SMBALERT/CONFIG SMBUS INTEL PCH HOST NOTIFY, or drivers/smbus/smbus stm32.c with CONFIG SMBUS STM32 SMBALERT), any user-mode thread that has been granted the SMBus device object can invoke these syscalls with an arbitrary pointer. The value reaches smbus callback remove() in drivers/smbus/smbus utils.h, which uses it as a node identity against the kernel's sys slist t of registered callbacks.
The consequence is that an unprivileged thread can unregister an SMBALERT or Host Notify callback that a supervisor-mode component registered, silently disabling alert handling for the rest of the system; because Zephyr images have fixed symbol addresses and the syscall returns 0 on a hit versus -ENOENT on a miss, the target address is both derivable and searchable. In builds with CONFIG ASSERT=y the ASSERT(callback->handler, ...) check additionally dereferences the caller-supplied address in supervisor mode, so a bogus pointer raises a kernel-mode fault and a fatal system error, and the fault/no-fault outcome discloses which addresses are mapped.
The fix removes both syscall entry points, demoting the two functions to ordinary static inline calls so that callback list manipulation is available only to supervisor-mode code. There is no impact on builds without CONFIG USERSPACE, and no impact on configurations that do not enable an SMBus driver with SMBALERT or Host Notify support.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-17053

Produtos afetados

Zephyr