PT-2026-104750 · Zephyrproject · Zephyr

CVE-2026-19185

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The system-call verifier for i3c do ccc() in drivers/i3c/i3c handlers.c validated the outer struct i3c ccc payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c ccc target payload carries its own data pointer and data len, and neither was passed through K SYSCALL MEMORY() before the payload was handed to z impl i3c do ccc() and on to the controller driver. The verifier also operated on the caller's live structure rather than a snapshot, so validated fields could be changed by a second user thread between the check and the driver's use — unlike the sibling z vrfy i3c transfer(), which has always copied its message array first.
The defect is only present in CONFIG USERSPACE builds, where drivers/i3c/i3c handlers.c is compiled. An unprivileged user-mode thread that has been granted access to the I3C controller device object — the ordinary way an application lets a user thread talk to I3C peripherals — can issue a direct CCC whose target payload data pointer names an arbitrary kernel address. Controller drivers dereference that pointer directly (for example drivers/i3c/i3c mcux.c, drivers/i3c/i3c cdns.c, drivers/i3c/i3c stm32.c, drivers/i3c/i3c npcx.c), using rnw to decide direction.
A read CCC therefore causes the kernel-mode driver to write bus-received bytes into an attacker-chosen kernel address for an attacker-chosen length, and a write CCC transmits kernel memory out onto the I3C bus. The result is an out-of-bounds kernel write plus a kernel memory disclosure, i.e. escalation from a user-mode thread to supervisor privilege, defeating the isolation CONFIG USERSPACE is meant to provide.
The fix introduces copy ccc and do(), which snapshots the payload, copies the target array into kernel memory with k usermode alloc from copy() (bounding num targets to fewer than 32), validates each per-target buffer with K SYSCALL MEMORY() according to rnw, and copies the driver-written num xfer and err fields back to the caller.

Fix

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19185

Affected Products

Zephyr