Userspace Memory Corruption in Zephyr RTIO Kernel Object Management
CVE-2026-16513
7.8HIGH
What is CVE-2026-16513?
The vulnerability occurs due to insufficient validation of the handle out-parameter in the RTIO API's userspace verifier. The function z_vrfy_rtio_sqe_copy_in_get_handles() allows user-mode threads with access to a struct rtio kernel object to invoke syscalls using arbitrary addresses for the handle. This results in the possibility of writing to any kernel address, leading to kernel memory corruption and potential escalation from user mode to kernel mode. The fix implements memory write checks to prevent unauthorized memory modifications, thus reinforcing the separation between user and kernel modes.
Affected Version(s)
zephyr 3.4.0 < 4.4.2
