目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-10682— Zephyr 日志过滤器设置系统调用验证器越界写入漏洞

一分钟漏洞结论

影响对象
zephyrproject zephyr
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Zephyr 内核中位于 的 系统调用对应的用户空间验证函数 ,对 类型的 参数进行了有符号比较: 。由于该比较是有符号的,任何负数值(例如 -1)都会轻易通过此检查,并被传递至 ,进而传播到 ,最终到达 。在该函数中, 被用作链接段数组 的无符号索引。 经过隐式转换为 后, 类型的 -1 变为 0xFFFFFFFF,导致对 数组的越界访问,从而引发内核对 段相邻内存的越界读(OOB read)以及越界读-改-写操作(涉及 宏)。 虽然写入的值是目标 32 位字中受限的 3 位日志级别槽位,但目标地址由攻击者选择(

CVSS 6.6 · Medium EPSS 0.17% · P6

影响版本矩阵 1

厂商产品 版本范围状态
zephyrproject zephyr 3.0.0< 4.5.0 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-10682 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace
来源: CVE Program / CVE List V5
Vulnerability Description
The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id parameter: src_id < (int16_t)log_src_cnt_get(domain_id). Any negative value for src_id (e.g. -1) trivially satisfied this check and was forwarded into z_impl_log_filter_set, where it propagated to filter_set() and ultimately to get_dynamic_filter(), which uses source_id as an unsigned index into the linker-section array &TYPE_SECTION_START(log_dynamic)[source_id].filters. After implicit conversion through uint32_t, an int16_t -1 becomes 0xFFFFFFFF, indexing log_dynamic far out of bounds and causing the kernel to perform an OOB read and an OOB read-modify-write (LOG_FILTER_SLOT_GET/SET) against memory adjacent to the log_dynamic section. The written value is a constrained 3-bit log level slot within the targeted 32-bit word, but the target address is attacker-chosen (a small negative offset from log_dynamic) and the write occurs in supervisor mode following a syscall from an unprivileged user thread, providing a kernel memory-corruption / privilege-escalation primitive. The defect is reachable on any build with CONFIG_USERSPACE=y and CONFIG_LOG_RUNTIME_FILTERING=y. Present from Zephyr v3.3.0 through v4.4.1. The fix replaces the signed bound check with an unsigned comparison: (uint32_t)src_id < log_src_cnt_get(domain_id), which correctly rejects negative inputs.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
zephyrproject zephyr 3.0.0 ~ 4.5.0 -

二、漏洞 CVE-2026-10682 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-10682 的情报信息

请登录查看更多情报信息。

CVE-2026-10682 补丁与修复 (1)

CVE-2026-10682 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-10682

暂无评论


发表评论