PT-2026-108755 · Zephyrproject · Zephyr
CVE-2026-19569
·
Publicado
2026-10-09
·
Atualizado
2026-10-09
CVSS v3.1
8.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
dynamic object create() in kernel/userspace/userspace.c computed the backing allocation for a dynamically allocated kernel object as obj size get(otype) + size, and for thread stack elements as STACK ELEMENT DATA SIZE(size) (a round-up plus fixed overhead), without checking either expression for unsigned wrap-around. A size close to SIZE MAX makes the computed total wrap to a very small value, so the heap chunk handed out is a few bytes while the object descriptor is still tagged with the full requested type and registered in the kernel object table.
The size argument reaches that arithmetic directly from user mode. k object alloc size() is declared syscall in include/zephyr/sys/kobject.h, its verifier z vrfy k object alloc size() in kernel/userspace/userspace handler.c is a bare pass-through, and z object alloc() only range-checks otype — nothing bounds size. The stack-element branch is additionally reachable through the k thread stack alloc() syscall via kernel/dynamic.c. Because subsequent kernel-object validation checks only the object's type and initialization state, the undersized handle passes K SYSCALL OBJ INIT()/K SYSCALL OBJ NEVER INIT(), and the matching init syscall (for example k mutex init(), k sem init(), or k thread create()) then writes a complete object over the truncated allocation.
An unprivileged user-mode thread can therefore trigger a supervisor-mode out-of-bounds write into the kernel resource-pool heap, of a size and content it substantially controls, corrupting sys heap chunk metadata and adjacent kernel objects. Under CONFIG GEN PRIV STACKS the thread-stack branch additionally stores an attacker-influenced wild pointer as a user thread's privileged stack base. The practical result is escape from the CONFIG USERSPACE sandbox — kernel-level code execution or at minimum kernel memory corruption and system compromise.
Exploitation requires CONFIG USERSPACE together with CONFIG DYNAMIC OBJECTS (also selected by CONFIG DYNAMIC THREAD under userspace), and a calling thread with an assigned resource pool. The fix rejects both overflowing computations and frees the partially built descriptor.
Correção
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zephyr