Flash Driver Vulnerability in SF32LB by Zephyr Project
CVE-2026-11743
6.6MEDIUM
What is CVE-2026-11743?
The SF32LB MPI QSPI NOR flash driver contains a vulnerability that arises from improper validation of flash offsets and lengths, particularly in read and write operations. An unprivileged thread can exploit this flaw by passing a crafted negative offset, resulting in unauthorized access to arbitrary memory. The driver fails to validate negative offsets effectively, allowing attackers to bypass security controls and access sensitive data. This vulnerability impacts both data integrity and availability, making it crucial for users and administrators to apply the recommended patches to mitigate potential security risks.
Affected Version(s)
zephyr 4.3.0 < 4.4.2
