Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18414— Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size validation

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: ADC API 要求每个驱动程序必须拒绝目标缓冲区过小的采样序列: 中 的 字段文档指出,“驱动程序必须确保样本写入不超过限制,并且如果缓冲区大小不足,必须返回错误”。然而,ADI MAX32 驱动程序并未遵守这一约定。 在 中, 函数将作为字节计数的 与样本计数( )进行比较,却忽略了 ,导致其接受了所需大小一半的缓冲区。随后,样本通过 函数以 类型的 进行存储。该函数每次写入两个字节(每个样本),并将指针前进一个 的长度:在同步读取时调用 ,在异步读取时调用 。例如,一个选择两

CVSS 7.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18414

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size validation
Source: CVE Program / CVE List V5
Vulnerability Description
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The ADI MAX32 driver did not honour that contract. start_read() in drivers/adc/adc_max32.c compared buffer_size, a byte count, against a sample count ((1 + extra_samplings) channels), ignoring sizeof(uint16_t), so it accepted a buffer half the required size. The samples are then stored through the uint16_t data->buffer by Wrap_MXC_ADC_GetData(), which writes two bytes per sample and advances the pointer by one uint16_t: in adc_max32_start_channel() for synchronous reads, and in adc_max32_isr() for asynchronous ones. A sequence selecting two channels with a two-byte buffer, for example, passes the check and has its second sample written past the end of the buffer. On a build with CONFIG_USERSPACE, adc_read() and adc_read_async() are system calls. The handler in drivers/adc/adc_handlers.c copies the sequence in from user memory, verifies only that [buffer, buffer + buffer_size) is writable by the calling thread, and rejects a user-supplied options->callback; it deliberately leaves the size arithmetic to the driver. A user-mode thread that has been granted access to a MAX32 ADC device object therefore fully controls channels, buffer, buffer_size and options->extra_samplings, and can make the driver write twice as many bytes as its buffer holds. Because the check scales with extra_samplings, the overrun equals the length of the buffer itself, up to channels * 65536 bytes past its end, since the sample pointer is only rewound on a repeat sampling, never on the extra samplings of a sequence. The resulting stores are performed by the driver in kernel mode (in the system call itself, the ADC context timer, or the ADC interrupt handler for asynchronous reads), where the MPU does not restrict the thread's memory domain, so the write walks linearly out of the user partition and into adjacent memory such as other partitions, kernel data or thread stacks. The impact is kernel-memory corruption of attacker-chosen length at an attacker-chosen offset, a plausible privilege-escalation and denial-of-service primitive from an unprivileged user-mode thread. Builds without CONFIG_USERSPACE are affected only as a caller-side robustness defect, since the application itself supplies the buffer. The fix replaces that check in start_read() with a call to the new shared helper adc_sequence_validate_buffer() in drivers/adc/adc_common.c, passing sizeof(uint16_t) as the sample size. The helper computes active_channels sizeof(uint16_t) (1 + extra_samplings) and returns -ENOMEM before any sampling is started.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 4.0.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-18414

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18414

请登录查看更多情报信息。

Other References for CVE-2026-18414 (3)

Same Patch Batch · zephyrproject · 2026-09-28 · 5 CVEs total

CVE-2026-16513 7.8 HIGH Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allo
CVE-2026-18413 7.8 HIGH Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer si
CVE-2026-18415 6.3 MEDIUM Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames
CVE-2026-18416 3.7 LOW Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_path_uri)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18414

No comments yet


Leave a comment