Impact
The vulnerability arises from user‑mode syscall verifiers in Zephyr's fuel gauge driver that declare variable‑length arrays based on an unvalidated len argument. These arrays are allocated before any permission check and are later copied from user memory without bounds checking. When a privileged task has access to a fuel‑gauge device, an attacker‑supplied len can overflow the supervisor stack and write arbitrary data into kernel memory, breaking out of the sandbox and potentially allowing kernel code execution or a crash.
Affected Systems
The flaw affects Zephyr RTOS projects that include the fuel gauge driver and run with CONFIG_USERSPACE enabled. It applies to any Zephyr release before the patch commit 0d65ce46… that removes the vulnerable verifiers. No specific product versions are listed, so all builds containing the unpatched driver are at risk.
Risk and Exploitability
The score is CVSS 7.8, indicating a high‑severity vulnerability. EPSS is not available, so the exact exploitation probability is unknown, but local users with access to the fuel gauge device can exploit the flaw by invoking the buggy syscalls with a large len value. The vulnerability is not yet catalogued in the CISA KEV, yet the potential for kernel‑level compromise warrants immediate remediation.
OpenCVE Enrichment