PT-2026-104749 · Zephyrproject · Zephyr

CVE-2026-19184

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
The NXP GAU ADC driver (drivers/adc/adc mcux gau adc.c) validated the caller-supplied sequence->buffer size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results length and used it in mcux gau adc read samples() as the number of uint16 t slots available. Because each conversion result occupies sizeof(uint16 t) bytes, a buffer that was accepted as "large enough" could be written with up to twice its size in bytes, so every sample past the buffer's midpoint was written out of bounds.
adc read() and adc read async() are Zephyr system calls. The syscall verifier in drivers/adc/adc handlers.c only confirms that the caller owns buffer size writable bytes (K SYSCALL MEMORY WRITE); deciding whether that size is sufficient for the requested channels and extra samplings is delegated entirely to the driver. On a build with CONFIG USERSPACE=y, a user-mode thread that has been granted the ADC device object could therefore submit a deliberately half-sized buffer and cause the driver's work-queue handler — which runs in supervisor mode, outside the caller's MPU restrictions — to write ADC conversion results past the end of that buffer, at an address and for a length of the caller's choosing.
The overrun is bounded by the requested sequence: with sequence->options->extra samplings set, the sampling loop walks the buffer pointer forward across every sampling, so the total overrun can reach the full size of the supplied buffer (kilobytes for a large extra samplings). The written words are 16-bit ADC conversion results, so the content is only partially attacker-influenced (via the selected analog input, gain and resolution), but the destination and length are fully controlled — sufficient for kernel memory corruption, a crash, or a userspace-to-kernel privilege escalation. Builds without CONFIG USERSPACE, or on SoCs other than NXP RW61x with the GAU ADC node enabled, are not exposed to the privilege boundary; there the same defect only causes a silent overflow when the application itself passes an undersized buffer.
The fix replaces the ad-hoc check with the shared adc sequence validate buffer() helper (validating against num channels * sizeof(uint16 t)), stores buffer size / sizeof(uint16 t) in results length, and corrects the loop bound to a post-decrement so exactly the available number of slots may be written.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19184

Affected Products

Zephyr