I3C Driver Vulnerability in Zephyr Project by Zephyr Project RTOS
CVE-2026-19185
7.8HIGH
What is CVE-2026-19185?
The I3C driver in the Zephyr Project is vulnerable due to inadequate validation of target data pointers within user-mode threads. An unprivileged thread can manipulate payloads to write to arbitrary kernel addresses or leak sensitive kernel memory, undermining isolation provided by CONFIG_USERSPACE. A fix has been implemented that ensures a snapshot of the payload is created, validating all data pointers before use to prevent unauthorized access.
Affected Version(s)
zephyr 3.2.0 < 4.5.0
