Description
The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The value func->cis.max_blk_size is decoded directly from the SDIO card's CIS FUNCE tuple in sdio_decode_cis() and is not validated. When a card reports a maximum block size of zero, size is always 0, remaining never decreases, and the loop spins forever.

The loop is reached from the public SDIO client API used by drivers, including sdio_read_fifo(), sdio_write_fifo(), and the incrementing register read/write helpers, each of which enters the loop while holding the per-card mutex func->card->lock. A card advertising max_blk_size == 0 therefore hangs the calling thread permanently on its first non-block-aligned transfer and never releases the mutex, denying service to the SDIO peripheral (and any subsystem such as Wi-Fi that depends on it) until the device is reset.

The malicious value must come from the SDIO card itself, so the defect is exploitable where a removable SDIO/combo card slot lets an attacker insert a crafted or malfunctioning card (a physical attack vector); on boards with a soldered SDIO peripheral it is not attacker-influenceable. There is no memory-safety, confidentiality, or integrity impact — only a permanent availability loss. The fix returns -EIO when func->cis.max_blk_size is zero, before the loop is entered.
Published: 2026-09-14
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (availability)
Action: Patch Immediately
AI Analysis

Impact

An infinite loop occurs in the Zephyr SDIO subsystem function sdio_io_rw_extended_helper() when the SDIO card reports a maximum block size of zero. The loop size calculation never reduces the remaining transfer size, causing the thread that performs the transfer to block indefinitely and to keep the per-card lock held. This permanently stalls all SDIO activity, including dependent subsystems such as Wi‑Fi, but does not affect data integrity or confidentiality.

Affected Systems

All Zephyr RTOS builds that include the SDIO subsystem and support removable SDIO card interfaces are affected, regardless of the specific Zephyr release version. The defect manifests when drivers invoke public SDIO client APIs such as sdio_read_fifo() or sdio_write_fifo().

Risk and Exploitability

The CVSS score is 4.6 and the EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a specially crafted SDIO card that reports a zero block size; therefore the attack vector is physical insertion of a malicious or malfunctioning card into a removable SDIO/combo slot. Devices with soldered SDIO peripherals are not susceptible. The effect is a permanent loss of availability for the SDIO peripheral and dependent subsystems until the device is reset or the card is removed.

Generated by OpenCVE AI on September 21, 2026 at 00:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zephyr to the patched version that returns -EIO when func->cis.max_blk_size is zero.
  • If an immediate update is not possible, remove or replace the SDIO card that reports a zero block size to prevent the lock from being held.
  • Configure the system to disable the SDIO slot if it is not required, or switch to a soldered SDIO peripheral to eliminate the attack surface.

Generated by OpenCVE AI on September 21, 2026 at 00:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The value func->cis.max_blk_size is decoded directly from the SDIO card's CIS FUNCE tuple in sdio_decode_cis() and is not validated. When a card reports a maximum block size of zero, size is always 0, remaining never decreases, and the loop spins forever. The loop is reached from the public SDIO client API used by drivers, including sdio_read_fifo(), sdio_write_fifo(), and the incrementing register read/write helpers, each of which enters the loop while holding the per-card mutex func->card->lock. A card advertising max_blk_size == 0 therefore hangs the calling thread permanently on its first non-block-aligned transfer and never releases the mutex, denying service to the SDIO peripheral (and any subsystem such as Wi-Fi that depends on it) until the device is reset. The malicious value must come from the SDIO card itself, so the defect is exploitable where a removable SDIO/combo card slot lets an attacker insert a crafted or malfunctioning card (a physical attack vector); on boards with a soldered SDIO peripheral it is not attacker-influenceable. There is no memory-safety, confidentiality, or integrity impact — only a permanent availability loss. The fix returns -EIO when func->cis.max_blk_size is zero, before the loop is entered.
Title Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk_size
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-14T19:40:10.205Z

Reserved: 2026-07-16T04:55:24.186Z

Link: CVE-2026-15923

cve-icon Vulnrichment

Updated: 2026-09-14T19:40:05.606Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T17:17:42.823

Modified: 2026-09-14T21:10:41.650

Link: CVE-2026-15923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')