Impact
The vulnerability lies in the i3c_do_ccc system‑call verifier, which checks the outer I3C CCC payload but does not validate the per‑target data pointers. A user‑mode task that has been granted access to the I3C controller device can craft a CCC with a target pointer that resolves to any kernel address. When the driver dereferences that pointer, the kernel may read or write up to the specified length, allowing an out‑of‑bounds write or disclosure. Because the caller can supply arbitrary addresses, an attacker can overwrite kernel data or leak sensitive information, resulting in privilege escalation from the unprivileged task to supervisor mode and breaking the isolation promised by CONFIG_USERSPACE.
Affected Systems
Zephyr Project Zephyr releases that enable CONFIG_USERSPACE and compile the i3c_handlers.c module are affected. The flaw is present in any build where the user‑space i3c do_ccc system call is included, regardless of device type. All such configurations that allow a user thread to open the I3C controller device without additional protective permissions are vulnerable until the patch from commit 35562f22 … is applied.
Risk and Exploitability
The CVSS score of 7.8 places the defect in the high severity category. The EPSS score is not available; however, no known public exploits are listed in CISA KEV. The likely attack vector is a local user‑mode application that has been granted access to the I3C controller; the attacker must craft a malicious CCC payload to target a kernel address. Successful exploitation results in kernel memory read/write, leading to privilege escalation. Because the flaw operates via a user‑space system call, remote exploitation would require a vulnerability that gives an attacker the ability to execute code in the context of a running Zephyr application.
OpenCVE Enrichment