PT-2026-102351 · Rtio · Rtio

·

CVE-2026-16513

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RTIO versions prior to 4.3.0
Description The userspace verifier function z vrfy rtio sqe copy in get handles() in subsys/rtio/rtio syscalls.c (and subsys/rtio/rtio handlers.c in earlier versions) fails to validate the handle out-parameter. This allows a user-mode thread with a struct rtio kernel object to provide an arbitrary address in the handle parameter. Because the system stores the kernel address of a submission-queue entry (SQE) through this pointer in supervisor mode without a K SYSCALL MEMORY WRITE check, it creates a write-what-where primitive. An attacker can use this to place a pointer to attacker-controlled data at any kernel address, potentially corrupting kernel function pointers, thread structures, or memory-domain partition tables. This can lead to kernel memory corruption, system crashes, or privilege escalation from user mode to kernel mode. This issue specifically affects builds configured with CONFIG USERSPACE and CONFIG RTIO.
Recommendations Update to version 4.3.0 or later to ensure the K SYSCALL MEMORY WRITE check is implemented for the handle parameter.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16513
GHSA-FWMC-Q8QG-JCXQ

Affected Products

Rtio