SMBus Driver API Vulnerability in Zephyr OS
CVE-2026-17053
What is CVE-2026-17053?
The SMBus driver API in Zephyr OS is vulnerable due to unvalidated user-supplied pointers being passed to kernel-mode driver code, specifically in the syscalls smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb(). This oversight allows unprivileged user-mode threads that have access to the SMBus device object to unregister critical callbacks, potentially leading to silent failures in alert handling across the system. A further risk exists when an assertion check in specific build configurations could lead to kernel-mode faults, exposing mapped addresses. The remedial actions taken include removing the vulnerable syscall entries and restricting callback manipulations to supervisor-mode code, ensuring enhanced security against unauthorized manipulations within the SMBus driver API.
Affected Version(s)
zephyr 3.4.0 < 4.4.2
