Buffer Overflow in ADI MAX32 Driver of Zephyr Project
CVE-2026-18414

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-18414?

A buffer overflow vulnerability exists in the ADI MAX32 driver of the Zephyr Project. The driver did not properly enforce buffer size constraints for sampling sequences, allowing an attacker with user-mode privileges to send requests that exceed the allocated buffer size. This issue arises from a failure to calculate the correct size required for storing multiple samples accurately. As a result, an attacker could exploit this vulnerability to corrupt kernel memory, leading to potential privilege escalation and denial-of-service scenarios. A fix has been implemented to validate buffer sizes correctly before processing sampling requests.

Affected Version(s)

zephyr 4.0.0 < 4.4.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.