Impact
A flaw in Zephyr’s zbus proxy agent IPC backend allows an out‑of‑bounds read when a rejected inter‑domain frame’s channel name is logged using a plain %s conversion. The channel_name field is a fixed‑size array that may not be NUL‑terminated, and the only termination check occurs after the frame is already rejected, causing the printf‑style formatter to walk past the frame’s bounds. The resulting strlen() can expose a few bytes of adjacent stack or shared memory and may trigger a fatal fault if the scan steps outside a mapped area. The weakness is a classic out‑of‑bounds read (CWE‑125).
Affected Systems
The vulnerability affects systems running the Zephyr real‑time operating system, specifically the subsys/zbus/proxy_agent implementation. No specific release or version information is provided in the advisory; the issue applies to any build that enables CONFIG_ZBUS_PROXY_AGENT_IPC and has logging at warning level or higher. An attacker must control a peer domain—typically a second core on the same SoC—to craft the malformed frame.
Risk and Exploitability
With a CVSS base score of 3.4 the risk is low and the vulnerability is limited to memory disclosure rather than code execution. EPSS data is not available and the issue is not listed in CISA KEV. The attack can be performed only when the attacker can supply a zbus frame to the IPC endpoint, so the threat is confined to embedded systems where multiple firmware domains are co‑resident on the same hardware. Absence of a publicly disclosed exploit and the requirement for firmware‑level control reduces the immediate exploitation likelihood, but the flaw remains relevant for audit and hardening of multi‑core devices.
OpenCVE Enrichment