Zephyr · Zephyr · CVE-2026-18413
**Name of the Vulnerable Software and Affected Versions**
Zephyr (affected versions not specified)
**Description**
The NXP MCUX LPADC driver fails to validate the destination buffer size before starting a sampling sequence. Specifically, the `mcux lpadc start read()` function in `drivers/adc/adc mcux lpadc.c` does not check if the buffer is large enough to hold the requested samples. This leads to an out-of-bounds write in `mcux lpadc isr()` for interrupt-driven builds and `mcux lpadc dma callback()` for DMA-driven builds.
In builds with `CONFIG USERSPACE` enabled, an unprivileged user-mode thread with access to an LPADC device object can manipulate `channels`, `buffer`, `buffer size`, and `options->extra samplings` to trigger kernel-memory corruption. Because the driver operates in kernel mode, it bypasses the Memory Protection Unit (MPU) restrictions, allowing writes into adjacent memory, kernel data, or thread stacks. This can result in privilege escalation or a denial-of-service. For builds without `CONFIG USERSPACE`, the issue is limited to a caller-side robustness defect.
**Recommendations**
Update the software to a version that implements the `adc sequence validate buffer()` helper function within `mcux lpadc start read()` to ensure the buffer size is validated before sampling begins.