目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-16513— RTIO系统调用验证器漏洞允许任意内核写入

一分钟漏洞结论

影响对象
zephyrproject zephyr
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

这段漏洞描述主要涉及 Zephyr 实时操作系统(RTOS)中 RTIO(Real-Time I/O)子系统的一个权限提升漏洞。以下是该描述信息的中文翻译: 在 中(v4.3.0 之前为 ),用户态验证器 验证了 RTIO 对象句柄(handle)和 输入数组,但并未验证句柄的输出参数(out-parameter)。在第一次循环迭代中,它执行了 ,通过一个直接从用户模式获取的指针,将新获取的提交队列入口(submission-queue entry)的内核地址存储起来,而在此之前没有进行 检查。 任何被授予 内核对

CVSS 7.8 · High

可能的 ATT&CK 技术 1 AI

T1055 · Process Injection
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-16513 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allows arbitrary kernel write
来源: CVE Program / CVE List V5
Vulnerability Description
The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On the first loop iteration it executed *handle = sqe, storing the kernel address of the newly acquired submission-queue entry through a pointer taken verbatim from user mode, with no K_SYSCALL_MEMORY_WRITE check in front of it. Any user-mode thread that has been granted a struct rtio kernel object can invoke the syscall with an arbitrary address in handle. That is the ordinary way an unprivileged thread uses the RTIO API, for example via sensor_read_async_mempool() or the async ADC helpers, which call rtio_sqe_copy_in_get_handles() internally. The store happens in supervisor mode before any submission-entry validation, so it fires regardless of whether the SQE contents are subsequently rejected. Only builds with CONFIG_USERSPACE and CONFIG_RTIO are affected; without CONFIG_USERSPACE the verifier is not compiled and the caller is already privileged. The write address is fully attacker-chosen and the written value is a pointer into the caller's own RTIO ring, whose contents the caller controls (the following *sqe = sqes[i] copies an attacker-supplied struct rtio_sqe into that slot). This yields a write-what-where primitive placing a pointer to attacker-controlled data at any kernel address, sufficient to corrupt kernel function pointers, thread structures, or memory-domain partition tables, and thus to escalate from user mode to kernel mode, defeating the isolation boundary CONFIG_USERSPACE is meant to enforce. At minimum it is a reliable kernel memory-corruption and crash primitive. The reporter reproduced the write on qemu_x86: a K_USER thread changed a supervisor global from NULL to a live kernel SQE pointer. The fix adds K_SYSCALL_MEMORY_WRITE(handle, sizeof(*handle)) (guarded by the existing optional-NULL semantics) before the loop, so the destination must lie in the calling thread's writable memory domain or the thread is terminated by K_OOPS. The neighbouring verifier z_vrfy_rtio_cqe_get_mempool_buffer(), which checked its buff/buff_len out-parameters only for read although the implementation writes through them, was hardened separately by bea93400138 ("rtio: syscalls: validate output params as writable"); that residual was materially weaker, since a read check still confines the target to the caller's own memory domain.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
zephyrproject zephyr 3.4.0 ~ 4.4.2 -

二、漏洞 CVE-2026-16513 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-16513 的情报信息

请登录查看更多情报信息。

CVE-2026-16513 其他参考 (2)

同批安全公告 · zephyrproject · 2026-09-28 · 共 5 条

CVE-2026-18413 7.8 HIGH NXP MCUX LPADC ADC驱动越界写入漏洞
CVE-2026-18414 7.8 HIGH ADI MAX32 ADC驱动越界写入漏洞
CVE-2026-18415 6.3 MEDIUM IEEE 802.15.4 L2发送路径越界写入漏洞
CVE-2026-18416 3.7 LOW CoAP well-known-core 边界读取漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-16513

暂无评论


发表评论