Buffer Overflow in ADI MAX32 Driver of Zephyr Project
CVE-2026-18414
7.8HIGH
What is CVE-2026-18414?
A buffer overflow vulnerability exists in the ADI MAX32 driver of the Zephyr Project. The driver did not properly enforce buffer size constraints for sampling sequences, allowing an attacker with user-mode privileges to send requests that exceed the allocated buffer size. This issue arises from a failure to calculate the correct size required for storing multiple samples accurately. As a result, an attacker could exploit this vulnerability to corrupt kernel memory, leading to potential privilege escalation and denial-of-service scenarios. A fix has been implemented to validate buffer sizes correctly before processing sampling requests.
Affected Version(s)
zephyr 4.0.0 < 4.4.2
