User-Mode Exploit in Fuel Gauge Syscall Handlers by Zephyr Project
CVE-2026-19669

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-19669?

An exploit allows attacker-controlled parameters to lead to out-of-bounds writes in the supervisor mode through user-mode syscall verifiers in Zephyr's fuel gauge drivers. The vulnerability arises from the use of unvalidated variable-length arrays without appropriate size checks, enabling users with permissions to trigger arbitrary memory writes. This can result in kernel code execution or system crashes, as attacker-supplied lengths and contents can corrupt memory beyond intended boundaries. The vulnerability has been addressed by improving input validation and removing unsafe copies.

Affected Version(s)

zephyr 3.4.0 < 4.5.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.