Information Disclosure in Zbus Proxy Agent IPC Backend by Zephyr
CVE-2026-18418
What is CVE-2026-18418?
The Zbus Proxy Agent in Zephyr's IPC backend is susceptible to an information disclosure vulnerability caused by improper logging of rejected inter-domain frames. Specifically, a plain %s conversion format in the logging mechanism can lead to the exposure of sensitive memory contents from adjacent stack data or shared memory, depending on the backend in use. This occurs when a peer domain transmits malformed frames, including those that do not correctly terminate the channel_name[] array. The lack of proper checks before logging leads to potentially revealing adjacent memory contents, underscoring a substantial risk if an attacker has control over the firmware of the peer domain. A corrective action has been implemented to restrict the logging format and ensure safe handling of such log operations.
Affected Version(s)
zephyr 4.4.0 < 4.4.2
