Stack-based Buffer Overflow in ELAN Smart-Pad by ELAN Microelectronics
CVE-2026-18909

5.6MEDIUM

Key Information:

Vendor
CVE Published:
6 August 2026

What is CVE-2026-18909?

A stack-based buffer overflow vulnerability in ELAN Smart-Pad on Windows can be exploited due to inadequate upper-bound checks during Intel SMBus recovery in ETDSMBus.sys. This flaw allows a malicious local user to send an out-of-bounds value to ETD.sys, resulting in a loop counter for a stack buffer copy being mishandled. This can lead to a kernel bugcheck, causing a denial of service with a BSOD error (0xF7 DRIVER_OVERRAN_STACK_BUFFER).

Affected Version(s)

ELAN Smart-Pad Windows 0

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.