User-Mode Exploit in Fuel Gauge Syscall Handlers by Zephyr Project
CVE-2026-19669
7.8HIGH
What is CVE-2026-19669?
An exploit allows attacker-controlled parameters to lead to out-of-bounds writes in the supervisor mode through user-mode syscall verifiers in Zephyr's fuel gauge drivers. The vulnerability arises from the use of unvalidated variable-length arrays without appropriate size checks, enabling users with permissions to trigger arbitrary memory writes. This can result in kernel code execution or system crashes, as attacker-supplied lengths and contents can corrupt memory beyond intended boundaries. The vulnerability has been addressed by improving input validation and removing unsafe copies.
Affected Version(s)
zephyr 3.4.0 < 4.5.0
