Description
The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_props[len], sized directly by the caller-supplied len argument. len is an unvalidated size_t taken straight from the syscall ABI, and the VLAs were allocated before any check at all — including before the K_SYSCALL_DRIVER_FUEL_GAUGE() object-permission check. The subsequent k_usermode_from_copy() calls validated only that the user source buffer was readable; the kernel destination was never bounds-checked, since it was sized by the same attacker-chosen len.

Any thread running in user mode with CONFIG_USERSPACE enabled can invoke fuel_gauge_get_props() or fuel_gauge_set_props() with a large len. This first displaces the supervisor stack pointer by an arbitrary attacker-chosen amount — Zephyr does not build with stack-clash probing, so the displacement itself does not fault, and the nested calls made by the verifier then write frames below the privileged stack. If the caller has been granted access to a fuel-gauge device object, the memcpy inside k_usermode_from_copy() additionally writes len * sizeof(union fuel_gauge_prop_val) bytes of fully attacker-controlled data starting well below the stack base. CONFIG_PRIVILEGED_STACK_SIZE defaults to 1024 bytes, so a len of roughly 170 already exhausts it.

The result is an out-of-bounds write in supervisor mode with attacker-controlled length and, on the permitted path, attacker-controlled content — a break out of the user-mode sandbox into kernel memory, leading to kernel code execution or a system crash. A stack guard region does not contain it, because the copy begins below the guard and walks upward, corrupting unprotected memory before the guard is reached. The fix removes the kernel-side copies entirely and validates the caller's arrays in place with K_SYSCALL_MEMORY_ARRAY_READ() / K_SYSCALL_MEMORY_ARRAY_WRITE(), which also handle the len * size multiplication overflow; this is safe because neither fuel_gauge_prop_t nor union fuel_gauge_prop_val contains embedded pointers.
Published: 2026-10-11
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Kernel stack overflow enabling kernel code execution or system crash
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from user‑mode syscall verifiers in Zephyr's fuel gauge driver that declare variable‑length arrays based on an unvalidated len argument. These arrays are allocated before any permission check and are later copied from user memory without bounds checking. When a privileged task has access to a fuel‑gauge device, an attacker‑supplied len can overflow the supervisor stack and write arbitrary data into kernel memory, breaking out of the sandbox and potentially allowing kernel code execution or a crash.

Affected Systems

The flaw affects Zephyr RTOS projects that include the fuel gauge driver and run with CONFIG_USERSPACE enabled. It applies to any Zephyr release before the patch commit 0d65ce46… that removes the vulnerable verifiers. No specific product versions are listed, so all builds containing the unpatched driver are at risk.

Risk and Exploitability

The score is CVSS 7.8, indicating a high‑severity vulnerability. EPSS is not available, so the exact exploitation probability is unknown, but local users with access to the fuel gauge device can exploit the flaw by invoking the buggy syscalls with a large len value. The vulnerability is not yet catalogued in the CISA KEV, yet the potential for kernel‑level compromise warrants immediate remediation.

Generated by OpenCVE AI on October 11, 2026 at 18:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Zephyr patch that removes the unsafe kernel‑side copies and replaces them with K_SYSCALL_MEMORY_ARRAY_READ/WRITE validations; the commit reference is https://github.com/zephyrproject-rtos/zephyr/commit/0d65ce46dda0626164503c50f37e6e1f59d310a9 or upgrade to a Zephyr release that includes this change.
  • Rebuild the Zephyr project and reinstall the firmware so that the updated driver is loaded.
  • If the patch cannot be applied immediately, restrict or disable the fuel gauge driver for untrusted user tasks so that only privileged system components can invoke its syscalls.

Generated by OpenCVE AI on October 11, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Sun, 11 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_props[len], sized directly by the caller-supplied len argument. len is an unvalidated size_t taken straight from the syscall ABI, and the VLAs were allocated before any check at all — including before the K_SYSCALL_DRIVER_FUEL_GAUGE() object-permission check. The subsequent k_usermode_from_copy() calls validated only that the user source buffer was readable; the kernel destination was never bounds-checked, since it was sized by the same attacker-chosen len. Any thread running in user mode with CONFIG_USERSPACE enabled can invoke fuel_gauge_get_props() or fuel_gauge_set_props() with a large len. This first displaces the supervisor stack pointer by an arbitrary attacker-chosen amount — Zephyr does not build with stack-clash probing, so the displacement itself does not fault, and the nested calls made by the verifier then write frames below the privileged stack. If the caller has been granted access to a fuel-gauge device object, the memcpy inside k_usermode_from_copy() additionally writes len * sizeof(union fuel_gauge_prop_val) bytes of fully attacker-controlled data starting well below the stack base. CONFIG_PRIVILEGED_STACK_SIZE defaults to 1024 bytes, so a len of roughly 170 already exhausts it. The result is an out-of-bounds write in supervisor mode with attacker-controlled length and, on the permitted path, attacker-controlled content — a break out of the user-mode sandbox into kernel memory, leading to kernel code execution or a system crash. A stack guard region does not contain it, because the copy begins below the guard and walks upward, corrupting unprotected memory before the guard is reached. The fix removes the kernel-side copies entirely and validates the caller's arrays in place with K_SYSCALL_MEMORY_ARRAY_READ() / K_SYSCALL_MEMORY_ARRAY_WRITE(), which also handle the len * size multiplication overflow; this is safe because neither fuel_gauge_prop_t nor union fuel_gauge_prop_val contains embedded pointers.
Title Unbounded variable-length array in fuel gauge syscall verifiers allows kernel stack overflow from user mode
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-10-11T17:14:51.720Z

Reserved: 2026-08-12T20:43:46.670Z

Link: CVE-2026-19669

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T18:16:58.563

Modified: 2026-10-11T18:16:58.563

Link: CVE-2026-19669

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T18:30:19Z

Weaknesses