Description
The zbus proxy agent IPC backend in subsys/zbus/proxy_agent/zbus_proxy_agent_ipc.c logged the channel name of a rejected inter-domain frame with a plain %s conversion. The frame type struct zbus_proxy_msg carries a fixed-size channel_name[] array as its last member, and nothing in the transport guarantees the array is NUL-terminated. The only code that verifies termination is zbus_proxy_agent_receive_cb() in subsys/zbus/proxy_agent/zbus_proxy_agent.c, which rejects the frame in precisely those cases — so the warning printed a non-terminated buffer exactly on the error paths where the name had been found invalid (or, for an invalid message_size, had not been inspected at all).

Any peer domain able to place a frame of sizeof(struct zbus_proxy_msg) bytes on the bound ipc_service endpoint can trigger it, by sending a frame with an out-of-range message_size or with channel_name[] containing no NUL byte. Reaching the code requires CONFIG_ZBUS_PROXY_AGENT_IPC and logging built at warning level or above (the default), and requires control over the firmware of the peer domain — typically a second core on the same SoC.

The resulting strlen() inside the log packager walks past the end of the frame object until it finds a zero byte. With the icmsg backend the frame lives in a stack buffer of the IPC work-queue thread, so bytes of that thread's stack are rendered into the log message; with the rpmsg backends the scan continues through the shared vring memory. Impact is bounded to disclosure of a small amount of adjacent memory into the receiving domain's log sink, plus a possible fatal fault if the scan leaves a mapped region; the log packager's own -ENOSPC bound prevents the overrun from becoming a write. The fix bounds the conversion with %.*s and MIN(msg->channel_name_len, sizeof(msg->channel_name)).
Published: 2026-10-11
Score: 3.4 Low
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Assess
AI Analysis

Impact

A flaw in Zephyr’s zbus proxy agent IPC backend allows an out‑of‑bounds read when a rejected inter‑domain frame’s channel name is logged using a plain %s conversion. The channel_name field is a fixed‑size array that may not be NUL‑terminated, and the only termination check occurs after the frame is already rejected, causing the printf‑style formatter to walk past the frame’s bounds. The resulting strlen() can expose a few bytes of adjacent stack or shared memory and may trigger a fatal fault if the scan steps outside a mapped area. The weakness is a classic out‑of‑bounds read (CWE‑125).

Affected Systems

The vulnerability affects systems running the Zephyr real‑time operating system, specifically the subsys/zbus/proxy_agent implementation. No specific release or version information is provided in the advisory; the issue applies to any build that enables CONFIG_ZBUS_PROXY_AGENT_IPC and has logging at warning level or higher. An attacker must control a peer domain—typically a second core on the same SoC—to craft the malformed frame.

Risk and Exploitability

With a CVSS base score of 3.4 the risk is low and the vulnerability is limited to memory disclosure rather than code execution. EPSS data is not available and the issue is not listed in CISA KEV. The attack can be performed only when the attacker can supply a zbus frame to the IPC endpoint, so the threat is confined to embedded systems where multiple firmware domains are co‑resident on the same hardware. Absence of a publicly disclosed exploit and the requirement for firmware‑level control reduces the immediate exploitation likelihood, but the flaw remains relevant for audit and hardening of multi‑core devices.

Generated by OpenCVE AI on October 11, 2026 at 18:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a Zephyr release that includes the bounding change in zbus_proxy_agent_ipc.c.
  • If the proxy agent IPC backend is not required, disable CONFIG_ZBUS_PROXY_AGENT_IPC in the build configuration.
  • Reduce the logging level for the zbus proxy agent to below warning to avoid triggering the formatted print when a frame is rejected.

Generated by OpenCVE AI on October 11, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Sun, 11 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description The zbus proxy agent IPC backend in subsys/zbus/proxy_agent/zbus_proxy_agent_ipc.c logged the channel name of a rejected inter-domain frame with a plain %s conversion. The frame type struct zbus_proxy_msg carries a fixed-size channel_name[] array as its last member, and nothing in the transport guarantees the array is NUL-terminated. The only code that verifies termination is zbus_proxy_agent_receive_cb() in subsys/zbus/proxy_agent/zbus_proxy_agent.c, which rejects the frame in precisely those cases — so the warning printed a non-terminated buffer exactly on the error paths where the name had been found invalid (or, for an invalid message_size, had not been inspected at all). Any peer domain able to place a frame of sizeof(struct zbus_proxy_msg) bytes on the bound ipc_service endpoint can trigger it, by sending a frame with an out-of-range message_size or with channel_name[] containing no NUL byte. Reaching the code requires CONFIG_ZBUS_PROXY_AGENT_IPC and logging built at warning level or above (the default), and requires control over the firmware of the peer domain — typically a second core on the same SoC. The resulting strlen() inside the log packager walks past the end of the frame object until it finds a zero byte. With the icmsg backend the frame lives in a stack buffer of the IPC work-queue thread, so bytes of that thread's stack are rendered into the log message; with the rpmsg backends the scan continues through the shared vring memory. Impact is bounded to disclosure of a small amount of adjacent memory into the receiving domain's log sink, plus a possible fatal fault if the scan leaves a mapped region; the log packager's own -ENOSPC bound prevents the overrun from becoming a write. The fix bounds the conversion with %.*s and MIN(msg->channel_name_len, sizeof(msg->channel_name)).
Title Out-of-bounds read when the zbus proxy agent IPC backend logs a rejected peer frame's channel name
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-10-11T17:15:00.221Z

Reserved: 2026-07-30T17:54:15.055Z

Link: CVE-2026-18418

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T18:16:58.113

Modified: 2026-10-11T18:16:58.113

Link: CVE-2026-18418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T18:30:19Z

Weaknesses