Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-10669— Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyr 3.7.0版本至4.4.0版本存在缓冲区错误漏洞,该漏洞源于arch_buffer_validate()函数默认返回值为0(允许访问),当缓冲区范围环绕32位地址空间时,导致MPU区域探测循环执行零次并返回允许访问,未授权用户模式线程可通过特制地址和大小参数绕过验证,导致信息泄露、内存破坏、权限提升和拒绝服务。

CVSS 7.8 · High EPSS 0.18% · P7

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 3.7.0< 4.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10669

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation
Source: CVE Program / CVE List V5
Vulnerability Description
On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the architecture hook that verifies a user-mode-supplied buffer is accessible to the calling user thread with the requested permission — defaulted its return value to 0 (access permitted) and only set a denial result inside its per-MPU-region probe loop. When the rounded extent of the buffer wraps the 32-bit address space (size + alignment offset near SIZE_MAX, or ROUND_UP(size + offset) overflowing to 0), the loop executes zero iterations and the function returns 0 = permitted without probing any MPU region. The syscall-layer pre-checks (K_SYSCALL_MEMORY_SIZE_CHECK / Z_DETECT_POINTER_OVERFLOW) only catch a raw addr+size wrap and do not cover the ROUND_UP-induced wrap, and the string path (arch_user_string_nlen -> arch_buffer_validate) has no syscall-layer guard at all. An unprivileged user-mode thread can therefore pass a crafted (addr, size) to any syscall that validates user buffers via k_usermode_from_copy/to_copy or k_usermode_string_copy and have validation succeed for memory it must not access; the kernel then reads from (disclosure) or, with write=1, writes to (corruption) attacker-chosen kernel or other-partition memory on the thread's behalf, enabling information disclosure, memory corruption, privilege escalation, and denial of service. Affected from v3.7.0 (when Xtensa MPU userspace support was added) through v4.4.0. The fix changes the default to -EINVAL (deny by default), adds an explicit size_add_overflow check, and sets the success value only after the full range has been validated.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5
Vulnerability Title
zephyrproject zephyr 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyr 3.7.0版本至4.4.0版本存在缓冲区错误漏洞,该漏洞源于arch_buffer_validate()函数默认返回值为0(允许访问),当缓冲区范围环绕32位地址空间时,导致MPU区域探测循环执行零次并返回允许访问,未授权用户模式线程可通过特制地址和大小参数绕过验证,导致信息泄露、内存破坏、权限提升和拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 3.7.0 ~ 4.5.0 -

II. Public POCs for CVE-2026-10669

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10669

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-10669 (1)

Vendor Advisories for CVE-2026-10669 (1)

Same Patch Batch · zephyrproject · 2026-07-14 · 4 CVEs total

CVE-2026-10672 8.2 HIGH Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)
CVE-2026-10671 7.1 HIGH User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_U
CVE-2026-10670 5.5 MEDIUM User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall v

IV. Related Vulnerabilities

V. Comments for CVE-2026-10669

No comments yet


Leave a comment