Description
The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c validated only the port device object and passed the caller-supplied timestamp and event_count output pointers to the driver without a K_SYSCALL_MEMORY_WRITE() check. The other handlers in the same file (z_vrfy_tgpio_port_get_time(), z_vrfy_tgpio_port_get_cycles_per_second()) already performed that check, so the omission left one syscall unguarded.

tgpio_pin_read_ts_ec() is declared __syscall, so with CONFIG_USERSPACE=y an unprivileged user-mode thread that has been granted access to the TGPIO device object can invoke it with arbitrary pointer values. tgpio_intel_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_intel.c bounds-checks only the pin index and then unconditionally performs timestamp = ... and event_count = ..., executing two 8-byte stores in supervisor mode at addresses chosen by the user-mode caller.

The result is a write-what-where primitive that crosses the userspace/kernel boundary: the target address is fully attacker-chosen and the stored values are the hardware time-capture and event-counter register contents. Corrupting kernel data structures this way can escalate the calling thread to supervisor privilege or crash the system; the device-object permission required is a narrow capability that is not intended to confer any kernel-memory access. The fix adds the two missing K_SYSCALL_MEMORY_WRITE() validations before the driver call.

Exposure is narrow in practice. Only builds with CONFIG_USERSPACE=y and CONFIG_TIMEAWARE_GPIO=y compile the affected file, and from v3.6.0 onward the file additionally referenced a relocated header (<zephyr/syscall_handler.h>) and removed Z_SYSCALL_* macros, so such a configuration failed to build until those were repaired after v4.4.0. Downstream trees that locally corrected that breakage, and v3.5.0 builds where it did not exist, are the exposed population.
Published: 2026-09-21
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Supervisor memory write – privilege escalation
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the tgpio_pin_read_ts_ec syscall handler of Zephyr's time‑aware GPIO subsystem. The handler accepts user‑supplied pointers for timestamp and event_count outputs without verifying that the caller can write to those memory addresses. The unprotected 8‑byte stores, executed in supervisor mode, give a user‑mode thread a write‑what‑where primitive that can corrupt kernel data structures, potentially leading to privilege escalation or a system crash. The weak point is a classic out‑of‑bounds write (CWE‑787).

Affected Systems

Affected only Zephyr releases that compiled with CONFIG_USERSPACE=y and CONFIG_TIMEAWARE_GPIO=y. The problem existed in source versions starting with v3.6.0 after a header relocation and was only rebuildable after the build was repaired in v4.4.0. Downstream trees that applied the needed fixes or built without the time‑aware GPIO were not exposed. The affected vendor product is Zephyr RTOS.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity with medium‑to‑high impact if exploited. EPSS is not available, so the current exploitation probability is unclear, but the vulnerability is a user‑land write‑what‑where, a pattern frequently exploited in practice. KEV lists the item as not mitigated. Exploitation requires an unprivileged thread that holds access to the TGPIO device object; with such capability the attacker can supply arbitrary pointers and force writes to kernel memory. The narrow build configuration and required user‑capability reduce the exposed attack surface but still present a serious risk for systems that enable userspace GPIO access.

Generated by OpenCVE AI on September 21, 2026 at 19:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Zephyr to a version that includes the patch adding K_SYSCALL_MEMORY_WRITE checks to tgpio_pin_read_ts_ec (see commit 26264fffc17c2174319394ffa274af3f6efdc221).
  • If an immediate patch cannot be applied, reconfigure the build to disable CONFIG_TIMEAWARE_GPIO or remove userspace access to the TGPIO device object so that no unprivileged thread can invoke the vulnerable syscall.
  • Audit or restrict the userspace capabilities granted to the TGPIO device, limiting them to only the minimal required functions to prevent privilege escalation when the patch is unavailable.

Generated by OpenCVE AI on September 21, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c validated only the port device object and passed the caller-supplied timestamp and event_count output pointers to the driver without a K_SYSCALL_MEMORY_WRITE() check. The other handlers in the same file (z_vrfy_tgpio_port_get_time(), z_vrfy_tgpio_port_get_cycles_per_second()) already performed that check, so the omission left one syscall unguarded. tgpio_pin_read_ts_ec() is declared __syscall, so with CONFIG_USERSPACE=y an unprivileged user-mode thread that has been granted access to the TGPIO device object can invoke it with arbitrary pointer values. tgpio_intel_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_intel.c bounds-checks only the pin index and then unconditionally performs timestamp = ... and event_count = ..., executing two 8-byte stores in supervisor mode at addresses chosen by the user-mode caller. The result is a write-what-where primitive that crosses the userspace/kernel boundary: the target address is fully attacker-chosen and the stored values are the hardware time-capture and event-counter register contents. Corrupting kernel data structures this way can escalate the calling thread to supervisor privilege or crash the system; the device-object permission required is a narrow capability that is not intended to confer any kernel-memory access. The fix adds the two missing K_SYSCALL_MEMORY_WRITE() validations before the driver call. Exposure is narrow in practice. Only builds with CONFIG_USERSPACE=y and CONFIG_TIMEAWARE_GPIO=y compile the affected file, and from v3.6.0 onward the file additionally referenced a relocated header (<zephyr/syscall_handler.h>) and removed Z_SYSCALL_* macros, so such a configuration failed to build until those were repaired after v4.4.0. Downstream trees that locally corrected that breakage, and v3.5.0 builds where it did not exist, are the exposed population.
Title Missing user-pointer validation in tgpio_pin_read_ts_ec syscall handler allows arbitrary supervisor-memory write from userspace
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-21T18:43:05.834Z

Reserved: 2026-07-24T13:31:05.682Z

Link: CVE-2026-17052

cve-icon Vulnrichment

Updated: 2026-09-21T18:43:00.801Z

cve-icon NVD

Status : Received

Published: 2026-09-21T19:17:04.080

Modified: 2026-09-21T19:17:04.080

Link: CVE-2026-17052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T20:00:13Z

Weaknesses