Description
The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) requires that context to be the first member because its callbacks cast user_data directly to struct gnss_nmea0183_match_data . In the affected releases match_data was the second member (after const struct device dev), so it sat at a non-zero offset while gnss_nmea0183_match_init() initialized it at the correct address. The registered NMEA handlers instead pass the whole device data object (data->devices.gnss->data, offset 0), producing an offset-shifted type confusion between where state is initialized and where the parse callbacks read and write it.

When NMEA sentences from the GNSS receiver are parsed, the GGA/RMC callbacks write parsed fix data into the wrong location within the struct, and the GSV callback (gnss_nmea0183_match_gsv_callback, active under CONFIG_GNSS_SATELLITES) reads its satellites pointer and bound from the wrong offsets — non-pointer bytes of struct hl78xx_gnss_data — and then writes parsed struct gnss_satellite entries through that bogus pointer. This is a write through an uninitialized/wild pointer with a garbage bound.

The NMEA handlers are registered by default (CONFIG_HL78XX_GNSS_SOURCE_NMEA is the default GNSS source) on devices using the HL78xx GNSS. The driver runs in kernel context and the NMEA data originates from the GNSS radio front-end, so a party able to influence the GNSS signal (for example GNSS/GPS spoofing at radio proximity) can drive the kernel-side parser into the faulty write. The most likely impact is a crash (denial of service) because the bogus pointer resolves to a fixed near-NULL value, with adjacent-memory corruption possible on MMU-less targets. Confidentiality is not affected. Exploitation requires the satellites feature to be enabled and active, so attack complexity is high.
Published: 2026-09-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Patch
AI Analysis

Impact

The vulnerability is a type‑confusion flaw in the Zephyr HL78xx GNSS NMEA driver that causes the kernel parser to write parsed data to a location that is determined by an uninitialized, wild pointer. The mismatch in struct layout results in writes to an incorrect memory region, potentially corrupting kernel memory or causing a crash. The flaw does not or, on MMU-less targets, possible memory corruption.

Affected Systems

Any Zephyr build that includes the HL78xx modem GNSS driver (drivers/modem/hl78xx/) and uses the default GNSS source (CONFIG_HL78XX_GNSS_SOURCE_NMEA) is affected. The issue is present in all releases that contain the buggy layout before the commit 8a2465784e8909aa3835559381a60c00cc2218a1. No specific product version numbers are provided, so all builds that have not applied this patch are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate impact. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting low to moderate exploitation probability. An attacker would need to spoof GNSS signals in proximity to the device and requires the satellite parsing feature (CONFIG_GNSS_SATELLITES) to be enabled, making the attack complexity high. The primary consequence is a kernel crash that could lead to denial of service.

Generated by OpenCVE AI on September 10, 2026 at 15:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Zephyr patch that moves gnss_nmea0183_match_data to the first member of hl78xx_gnss_data, as described in commit 8a2465784e8909aa3835559381a60c00cc2218a1 or upgrade to the latest Zephyr release.
  • If upgrading is not immediately possible, disable the HL78xx GNSS NMEA source by turning off CONFIG_HL78XX_GNSS_SOURCE_NMEA or, if the satellite feature must remain, disable CONFIG_GNSS_SATELLITES to prevent the wild-pointer write callbacks from executing.
  • Monitor system stability for kernel panics or memory corruption after GNSS data is processed, and verify that no wildcard pointer writes occur.

Generated by OpenCVE AI on September 10, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) requires that context to be the first member because its callbacks cast user_data directly to struct gnss_nmea0183_match_data . In the affected releases match_data was the second member (after const struct device dev), so it sat at a non-zero offset while gnss_nmea0183_match_init() initialized it at the correct address. The registered NMEA handlers instead pass the whole device data object (data->devices.gnss->data, offset 0), producing an offset-shifted type confusion between where state is initialized and where the parse callbacks read and write it. When NMEA sentences from the GNSS receiver are parsed, the GGA/RMC callbacks write parsed fix data into the wrong location within the struct, and the GSV callback (gnss_nmea0183_match_gsv_callback, active under CONFIG_GNSS_SATELLITES) reads its satellites pointer and bound from the wrong offsets — non-pointer bytes of struct hl78xx_gnss_data — and then writes parsed struct gnss_satellite entries through that bogus pointer. This is a write through an uninitialized/wild pointer with a garbage bound. The NMEA handlers are registered by default (CONFIG_HL78XX_GNSS_SOURCE_NMEA is the default GNSS source) on devices using the HL78xx GNSS. The driver runs in kernel context and the NMEA data originates from the GNSS radio front-end, so a party able to influence the GNSS signal (for example GNSS/GPS spoofing at radio proximity) can drive the kernel-side parser into the faulty write. The most likely impact is a crash (denial of service) because the bogus pointer resolves to a fixed near-NULL value, with adjacent-memory corruption possible on MMU-less targets. Confidentiality is not affected. Exploitation requires the satellites feature to be enabled and active, so attack complexity is high.
Title Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-10T16:58:19.058Z

Reserved: 2026-07-10T20:12:01.873Z

Link: CVE-2026-15461

cve-icon Vulnrichment

Updated: 2026-09-10T16:58:02.696Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T15:17:25.060

Modified: 2026-09-10T17:17:01.853

Link: CVE-2026-15461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:00:08Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')