Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-16513— Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allows arbitrary kernel write

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

这段漏洞描述主要涉及 Zephyr 实时操作系统(RTOS)中 RTIO(Real-Time I/O)子系统的一个权限提升漏洞。以下是该描述信息的中文翻译: 在 中(v4.3.0 之前为 ),用户态验证器 验证了 RTIO 对象句柄(handle)和 输入数组,但并未验证句柄的输出参数(out-parameter)。在第一次循环迭代中,它执行了 ,通过一个直接从用户模式获取的指针,将新获取的提交队列入口(submission-queue entry)的内核地址存储起来,而在此之前没有进行 检查。 任何被授予 内核对

CVSS 7.8 · High

Possible ATT&CK Techniques 1 AI

T1055 · Process Injection
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-16513

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allows arbitrary kernel write
Source: CVE Program / CVE List V5
Vulnerability Description
The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On the first loop iteration it executed *handle = sqe, storing the kernel address of the newly acquired submission-queue entry through a pointer taken verbatim from user mode, with no K_SYSCALL_MEMORY_WRITE check in front of it. Any user-mode thread that has been granted a struct rtio kernel object can invoke the syscall with an arbitrary address in handle. That is the ordinary way an unprivileged thread uses the RTIO API, for example via sensor_read_async_mempool() or the async ADC helpers, which call rtio_sqe_copy_in_get_handles() internally. The store happens in supervisor mode before any submission-entry validation, so it fires regardless of whether the SQE contents are subsequently rejected. Only builds with CONFIG_USERSPACE and CONFIG_RTIO are affected; without CONFIG_USERSPACE the verifier is not compiled and the caller is already privileged. The write address is fully attacker-chosen and the written value is a pointer into the caller's own RTIO ring, whose contents the caller controls (the following *sqe = sqes[i] copies an attacker-supplied struct rtio_sqe into that slot). This yields a write-what-where primitive placing a pointer to attacker-controlled data at any kernel address, sufficient to corrupt kernel function pointers, thread structures, or memory-domain partition tables, and thus to escalate from user mode to kernel mode, defeating the isolation boundary CONFIG_USERSPACE is meant to enforce. At minimum it is a reliable kernel memory-corruption and crash primitive. The reporter reproduced the write on qemu_x86: a K_USER thread changed a supervisor global from NULL to a live kernel SQE pointer. The fix adds K_SYSCALL_MEMORY_WRITE(handle, sizeof(*handle)) (guarded by the existing optional-NULL semantics) before the loop, so the destination must lie in the calling thread's writable memory domain or the thread is terminated by K_OOPS. The neighbouring verifier z_vrfy_rtio_cqe_get_mempool_buffer(), which checked its buff/buff_len out-parameters only for read although the implementation writes through them, was hardened separately by bea93400138 ("rtio: syscalls: validate output params as writable"); that residual was materially weaker, since a read check still confines the target to the caller's own memory domain.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 3.4.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-16513

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16513

请登录查看更多情报信息。

Other References for CVE-2026-16513 (2)

Same Patch Batch · zephyrproject · 2026-09-28 · 5 CVEs total

CVE-2026-18413 7.8 HIGH Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer si
CVE-2026-18414 7.8 HIGH Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size
CVE-2026-18415 6.3 MEDIUM Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames
CVE-2026-18416 3.7 LOW Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_path_uri)

IV. Related Vulnerabilities

V. Comments for CVE-2026-16513

No comments yet


Leave a comment