PT-2026-102352 · Zephyr · Zephyr
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zephyr (affected versions not specified)
Description
The NXP MCUX LPADC driver fails to validate the destination buffer size before starting a sampling sequence. Specifically, the
mcux lpadc start read() function in drivers/adc/adc mcux lpadc.c does not check if the buffer is large enough to hold the requested samples. This leads to an out-of-bounds write in mcux lpadc isr() for interrupt-driven builds and mcux lpadc dma callback() for DMA-driven builds.In builds with
CONFIG USERSPACE enabled, an unprivileged user-mode thread with access to an LPADC device object can manipulate channels, buffer, buffer size, and options->extra samplings to trigger kernel-memory corruption. Because the driver operates in kernel mode, it bypasses the Memory Protection Unit (MPU) restrictions, allowing writes into adjacent memory, kernel data, or thread stacks. This can result in privilege escalation or a denial-of-service. For builds without CONFIG USERSPACE, the issue is limited to a caller-side robustness defect.Recommendations
Update the software to a version that implements the
adc sequence validate buffer() helper function within mcux lpadc start read() to ensure the buffer size is validated before sampling begins.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zephyr