PT-2026-102353 · Zephyr · Zephyr
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zephyr (affected versions not specified)
Description
The ADI MAX32 driver fails to properly validate the destination buffer size for sampling sequences. The
start read() function in drivers/adc/adc max32.c compares the buffer size byte count against a sample count without considering the size of a uint16 t, allowing buffers half the required size to be accepted. This leads to an out-of-bounds write when samples are stored via Wrap MXC ADC GetData() in adc max32 start channel() for synchronous reads or adc max32 isr() for asynchronous reads.In builds with
CONFIG USERSPACE, where adc read() and adc read async() are system calls, an unprivileged user-mode thread with access to a MAX32 ADC device can control channels, buffer, buffer size, and options->extra samplings. This allows the driver to write beyond the buffer limit in kernel mode, bypassing MPU restrictions and corrupting adjacent kernel memory, other partitions, or thread stacks. This can result in privilege escalation or a denial-of-service.Recommendations
Update the
start read() function to use the adc sequence validate buffer() helper in drivers/adc/adc common.c to correctly validate the buffer size based on the sample size of uint16 t.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zephyr