PT-2026-102353 · Zephyr · Zephyr

·

CVE-2026-18414

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zephyr (affected versions not specified)
Description The ADI MAX32 driver fails to properly validate the destination buffer size for sampling sequences. The start read() function in drivers/adc/adc max32.c compares the buffer size byte count against a sample count without considering the size of a uint16 t, allowing buffers half the required size to be accepted. This leads to an out-of-bounds write when samples are stored via Wrap MXC ADC GetData() in adc max32 start channel() for synchronous reads or adc max32 isr() for asynchronous reads.
In builds with CONFIG USERSPACE, where adc read() and adc read async() are system calls, an unprivileged user-mode thread with access to a MAX32 ADC device can control channels, buffer, buffer size, and options->extra samplings. This allows the driver to write beyond the buffer limit in kernel mode, bypassing MPU restrictions and corrupting adjacent kernel memory, other partitions, or thread stacks. This can result in privilege escalation or a denial-of-service.
Recommendations Update the start read() function to use the adc sequence validate buffer() helper in drivers/adc/adc common.c to correctly validate the buffer size based on the sample size of uint16 t.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18414
GHSA-GHM4-78MM-8V2C

Affected Products

Zephyr