Description
The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results_length and used it in mcux_gau_adc_read_samples() as the number of uint16_t slots available. Because each conversion result occupies sizeof(uint16_t) bytes, a buffer that was accepted as "large enough" could be written with up to twice its size in bytes, so every sample past the buffer's midpoint was written out of bounds.

adc_read() and adc_read_async() are Zephyr system calls. The syscall verifier in drivers/adc/adc_handlers.c only confirms that the caller owns buffer_size writable bytes (K_SYSCALL_MEMORY_WRITE); deciding whether that size is sufficient for the requested channels and extra_samplings is delegated entirely to the driver. On a build with CONFIG_USERSPACE=y, a user-mode thread that has been granted the ADC device object could therefore submit a deliberately half-sized buffer and cause the driver's work-queue handler — which runs in supervisor mode, outside the caller's MPU restrictions — to write ADC conversion results past the end of that buffer, at an address and for a length of the caller's choosing.

The overrun is bounded by the requested sequence: with sequence->options->extra_samplings set, the sampling loop walks the buffer pointer forward across every sampling, so the total overrun can reach the full size of the supplied buffer (kilobytes for a large extra_samplings). The written words are 16-bit ADC conversion results, so the content is only partially attacker-influenced (via the selected analog input, gain and resolution), but the destination and length are fully controlled — sufficient for kernel memory corruption, a crash, or a userspace-to-kernel privilege escalation. Builds without CONFIG_USERSPACE, or on SoCs other than NXP RW61x with the GAU ADC node enabled, are not exposed to the privilege boundary; there the same defect only causes a silent overflow when the application itself passes an undersized buffer.

The fix replaces the ad-hoc check with the shared adc_sequence_validate_buffer() helper (validating against num_channels * sizeof(uint16_t)), stores buffer_size / sizeof(uint16_t) in results_length, and corrects the loop bound to a post-decrement so exactly the available number of slots may be written.
Published: 2026-10-05
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: Unbounded buffer write in Zephyr NXP GAU ADC driver allowing kernel memory corruption or privilege escalation in user space
Action: Apply Patch
AI Analysis

Impact

The NXP GAU ADC driver validates the caller supplied buffer size in bytes against the number of active channels, a sample count, and then stores the byte count in a length field used as a uint16_t slot count. Because each ADC conversion occupies two bytes, a half‑sized buffer can be written with up to twice its declared size. This causes an out‑of‑bounds write of 16‑bit conversion results. When performed from user mode, the write occurs in supervisor mode and is not subject to the caller's memory protection, so the attacker can overwrite arbitrary kernel memory, crash the system, or achieve user‑space to kernel privilege escalation. In non‑user‑space builds or with other SoCs the defect only causes a silent overflow and does not cross privilege boundaries.

Affected Systems

Affected product is the Zephyr RTOS ADC subsystem, specifically the NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c). The vulnerability exists in builds that enable CONFIG_USERSPACE and on NXP RW61x microcontrollers that expose the GAU ADC node. All Zephyr users deploying this driver on such hardware are potentially impacted; no specific Zephyr release versions are listed in the data.

Risk and Exploitability

The CVSS score of 8.4 classifies this flaw as High severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The vulnerability is locally exploitable only by a user‑mode thread that has been granted access to the ADC device. An attacker can provide a deliberately undersized buffer to adc_read() or adc_read_async(), triggering the driver’s supervisor‑mode work­queue handler to overwrite memory beyond the buffer’s boundary. The exploit is bounded by the configured sequence length and can overwrite a full buffer of kilobytes, offering sufficient control to corrupt kernel data or crash the system. Because the attack requires the specific build configuration and hardware, the overall likelihood is moderate, but the impact is severe if achieved.

Generated by OpenCVE AI on October 5, 2026 at 09:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Zephyr RTOS source to a version including the patch at commit 82b11958065aa85f8644ddc318ff4a328d1443c8 or later.
  • Rebuild the firmware for the target NXP RW61x board ensuring CONFIG_USERSPACE=y and the GAU ADC node are correctly configured with the updated driver code.
  • If the ADC functionality is not required, disable the NXP GAU ADC driver in the board configuration or remove the CONFIG_NXP_GAU_ADC option to prevent the vulnerable code path from being compiled.

Generated by OpenCVE AI on October 5, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Mon, 05 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Description The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results_length and used it in mcux_gau_adc_read_samples() as the number of uint16_t slots available. Because each conversion result occupies sizeof(uint16_t) bytes, a buffer that was accepted as "large enough" could be written with up to twice its size in bytes, so every sample past the buffer's midpoint was written out of bounds. adc_read() and adc_read_async() are Zephyr system calls. The syscall verifier in drivers/adc/adc_handlers.c only confirms that the caller owns buffer_size writable bytes (K_SYSCALL_MEMORY_WRITE); deciding whether that size is sufficient for the requested channels and extra_samplings is delegated entirely to the driver. On a build with CONFIG_USERSPACE=y, a user-mode thread that has been granted the ADC device object could therefore submit a deliberately half-sized buffer and cause the driver's work-queue handler — which runs in supervisor mode, outside the caller's MPU restrictions — to write ADC conversion results past the end of that buffer, at an address and for a length of the caller's choosing. The overrun is bounded by the requested sequence: with sequence->options->extra_samplings set, the sampling loop walks the buffer pointer forward across every sampling, so the total overrun can reach the full size of the supplied buffer (kilobytes for a large extra_samplings). The written words are 16-bit ADC conversion results, so the content is only partially attacker-influenced (via the selected analog input, gain and resolution), but the destination and length are fully controlled — sufficient for kernel memory corruption, a crash, or a userspace-to-kernel privilege escalation. Builds without CONFIG_USERSPACE, or on SoCs other than NXP RW61x with the GAU ADC node enabled, are not exposed to the privilege boundary; there the same defect only causes a silent overflow when the application itself passes an undersized buffer. The fix replaces the ad-hoc check with the shared adc_sequence_validate_buffer() helper (validating against num_channels * sizeof(uint16_t)), stores buffer_size / sizeof(uint16_t) in results_length, and corrects the loop bound to a post-decrement so exactly the available number of slots may be written.
Title Out-of-bounds write in the NXP GAU ADC driver due to byte-versus-sample buffer size validation mismatch
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-10-05T08:06:22.681Z

Reserved: 2026-08-06T18:36:10.589Z

Link: CVE-2026-19184

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:12.907

Modified: 2026-10-05T09:17:12.907

Link: CVE-2026-19184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T09:30:10Z

Weaknesses