目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-19575— 设备去初始化系统调用类型混淆可导致远程代码执行漏洞

一分钟漏洞结论

影响对象
zephyrproject zephyr
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

以下是该漏洞描述信息的中文翻译: 在 中,设备销毁( )系统调用的用户模式验证处理函数 使用 对其 参数进行验证。由于 在请求类型为 时会短路(跳过)类型比较,因此该检查仅简化为“此指针是调用线程被授予权限的某个内核对象的基地址”——对象的实际类型从未被比较,且 也跳过了初始化状态检查。而同伴处理函数 和 已使用 ,因此不受此影响。 因此,在用户模式下运行的线程可以传递任何它拥有权限的内核对象——最有价值的是通过 系统调用获得的线程栈对象,或为生成子用户线程而授予权限的静态定义的 ——只要其底层内存可从用户模式写入

CVSS 7.8 · High
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-19575 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Type confusion in the device_deinit system call allows user-mode threads to execute arbitrary kernel code
来源: CVE Program / CVE List V5
Vulnerability Description
The user-mode verification handler for the device_deinit() system call, z_vrfy_device_deinit() in kernel/device.c, validated its dev argument with K_SYSCALL_OBJ_INIT(dev, K_OBJ_ANY). k_object_validate() short-circuits its type comparison when the requested type is K_OBJ_ANY, so the check reduced to "this pointer is the base address of some kernel object the calling thread has been granted" — the object's actual type was never compared, and K_SYSCALL_OBJ_INIT also skips the initialization-state check. The sibling handlers z_vrfy_device_init() and z_vrfy_device_is_ready() already used K_OBJ_DRIVER_ANY and were unaffected. A thread running in user mode can therefore pass any kernel object it holds permission on — most usefully a thread stack object obtained from the k_thread_stack_alloc() syscall or a statically defined K_THREAD_STACK it was granted in order to spawn a child user thread — whose backing memory is writable from user mode. z_impl_device_deinit() then interprets those attacker-written bytes as a struct device: it dereferences the state pointer read out of the object, calls the function pointer read out of ops.deinit, and on success writes through state again. The result is an indirect call to an arbitrary address executed in supervisor mode, plus an arbitrary kernel read and a single-byte kernel write. Exploitation gives a local unprivileged thread full kernel code execution, defeating the CONFIG_USERSPACE isolation boundary entirely; a less precise attempt yields a supervisor-mode fault and a system crash. The defect is only reachable in builds that enable both CONFIG_USERSPACE and CONFIG_DEVICE_DEINIT_SUPPORT — with de-initialization support disabled, z_impl_device_deinit() returns -ENOTSUP without ever dereferencing the pointer. In v4.2.x and v4.3.x, CONFIG_DEVICE_DEINIT_SUPPORT defaulted to y, so every CONFIG_USERSPACE build of those releases is exposed unless the option was explicitly turned off. From v4.4.0 the option is opt-in (no default, and not selected by any in-tree subsystem), so a v4.4.x build is exposed only if it enables the option explicitly. The v4.2 line is no longer maintained and receives no backport. The fix changes the object check to K_OBJ_DRIVER_ANY, which constrains the argument to the build-generated driver object type range (K_OBJ_DRIVER_FIRST..K_OBJ_DRIVER_LAST) — the real struct device instances placed by the linker — so the state and ops.deinit fields are once again kernel-controlled.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
zephyrproject zephyr 4.2.0 ~ 4.4.2 -

二、漏洞 CVE-2026-19575 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-19575 的情报信息

请登录查看更多情报信息。

CVE-2026-19575 补丁与修复 (1)

CVE-2026-19575 厂商安全公告 (1)

同批安全公告 · zephyrproject · 2026-10-09 · 共 5 条

CVE-2026-19570 8.8 HIGH LE Audio广播接收端越界写入漏洞
CVE-2026-19569 8.8 HIGH 动态内核对象分配的整型溢出导致内核堆被破坏
CVE-2026-19574 7.0 HIGH ARM64 MMU内存域分配漏洞导致用户模式内存隔离失效
CVE-2026-19571 6.7 MEDIUM ITE IT8xxx2 SPI竞争条件漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-19575

暂无评论


发表评论