PT-2026-102351 · Rtio · Rtio
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RTIO versions prior to 4.3.0
Description
The userspace verifier function
z vrfy rtio sqe copy in get handles() in subsys/rtio/rtio syscalls.c (and subsys/rtio/rtio handlers.c in earlier versions) fails to validate the handle out-parameter. This allows a user-mode thread with a struct rtio kernel object to provide an arbitrary address in the handle parameter. Because the system stores the kernel address of a submission-queue entry (SQE) through this pointer in supervisor mode without a K SYSCALL MEMORY WRITE check, it creates a write-what-where primitive. An attacker can use this to place a pointer to attacker-controlled data at any kernel address, potentially corrupting kernel function pointers, thread structures, or memory-domain partition tables. This can lead to kernel memory corruption, system crashes, or privilege escalation from user mode to kernel mode. This issue specifically affects builds configured with CONFIG USERSPACE and CONFIG RTIO.Recommendations
Update to version 4.3.0 or later to ensure the
K SYSCALL MEMORY WRITE check is implemented for the handle parameter.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rtio