Impact
The NXP GAU ADC driver validates the caller supplied buffer size in bytes against the number of active channels, a sample count, and then stores the byte count in a length field used as a uint16_t slot count. Because each ADC conversion occupies two bytes, a half‑sized buffer can be written with up to twice its declared size. This causes an out‑of‑bounds write of 16‑bit conversion results. When performed from user mode, the write occurs in supervisor mode and is not subject to the caller's memory protection, so the attacker can overwrite arbitrary kernel memory, crash the system, or achieve user‑space to kernel privilege escalation. In non‑user‑space builds or with other SoCs the defect only causes a silent overflow and does not cross privilege boundaries.
Affected Systems
Affected product is the Zephyr RTOS ADC subsystem, specifically the NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c). The vulnerability exists in builds that enable CONFIG_USERSPACE and on NXP RW61x microcontrollers that expose the GAU ADC node. All Zephyr users deploying this driver on such hardware are potentially impacted; no specific Zephyr release versions are listed in the data.
Risk and Exploitability
The CVSS score of 8.4 classifies this flaw as High severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The vulnerability is locally exploitable only by a user‑mode thread that has been granted access to the ADC device. An attacker can provide a deliberately undersized buffer to adc_read() or adc_read_async(), triggering the driver’s supervisor‑mode workqueue handler to overwrite memory beyond the buffer’s boundary. The exploit is bounded by the configured sequence length and can overwrite a full buffer of kilobytes, offering sufficient control to corrupt kernel data or crash the system. Because the attack requires the specific build configuration and hardware, the overall likelihood is moderate, but the impact is severe if achieved.
OpenCVE Enrichment