Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19575— Type confusion in the device_deinit system call allows user-mode threads to execute arbitrary kernel code

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 在 中,设备销毁( )系统调用的用户模式验证处理函数 使用 对其 参数进行验证。由于 在请求类型为 时会短路(跳过)类型比较,因此该检查仅简化为“此指针是调用线程被授予权限的某个内核对象的基地址”——对象的实际类型从未被比较,且 也跳过了初始化状态检查。而同伴处理函数 和 已使用 ,因此不受此影响。 因此,在用户模式下运行的线程可以传递任何它拥有权限的内核对象——最有价值的是通过 系统调用获得的线程栈对象,或为生成子用户线程而授予权限的静态定义的 ——只要其底层内存可从用户模式写入

CVSS 7.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19575

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Type confusion in the device_deinit system call allows user-mode threads to execute arbitrary kernel code
Source: CVE Program / CVE List V5
Vulnerability Description
The user-mode verification handler for the device_deinit() system call, z_vrfy_device_deinit() in kernel/device.c, validated its dev argument with K_SYSCALL_OBJ_INIT(dev, K_OBJ_ANY). k_object_validate() short-circuits its type comparison when the requested type is K_OBJ_ANY, so the check reduced to "this pointer is the base address of some kernel object the calling thread has been granted" — the object's actual type was never compared, and K_SYSCALL_OBJ_INIT also skips the initialization-state check. The sibling handlers z_vrfy_device_init() and z_vrfy_device_is_ready() already used K_OBJ_DRIVER_ANY and were unaffected. A thread running in user mode can therefore pass any kernel object it holds permission on — most usefully a thread stack object obtained from the k_thread_stack_alloc() syscall or a statically defined K_THREAD_STACK it was granted in order to spawn a child user thread — whose backing memory is writable from user mode. z_impl_device_deinit() then interprets those attacker-written bytes as a struct device: it dereferences the state pointer read out of the object, calls the function pointer read out of ops.deinit, and on success writes through state again. The result is an indirect call to an arbitrary address executed in supervisor mode, plus an arbitrary kernel read and a single-byte kernel write. Exploitation gives a local unprivileged thread full kernel code execution, defeating the CONFIG_USERSPACE isolation boundary entirely; a less precise attempt yields a supervisor-mode fault and a system crash. The defect is only reachable in builds that enable both CONFIG_USERSPACE and CONFIG_DEVICE_DEINIT_SUPPORT — with de-initialization support disabled, z_impl_device_deinit() returns -ENOTSUP without ever dereferencing the pointer. In v4.2.x and v4.3.x, CONFIG_DEVICE_DEINIT_SUPPORT defaulted to y, so every CONFIG_USERSPACE build of those releases is exposed unless the option was explicitly turned off. From v4.4.0 the option is opt-in (no default, and not selected by any in-tree subsystem), so a v4.4.x build is exposed only if it enables the option explicitly. The v4.2 line is no longer maintained and receives no backport. The fix changes the object check to K_OBJ_DRIVER_ANY, which constrains the argument to the build-generated driver object type range (K_OBJ_DRIVER_FIRST..K_OBJ_DRIVER_LAST) — the real struct device instances placed by the linker — so the state and ops.deinit fields are once again kernel-controlled.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 4.2.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-19575

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19575

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-19575 (1)

Vendor Advisories for CVE-2026-19575 (1)

Same Patch Batch · zephyrproject · 2026-10-09 · 5 CVEs total

CVE-2026-19570 8.8 HIGH Out-of-bounds write in LE Audio Broadcast Sink when copying BASE subgroup metadata into th
CVE-2026-19569 8.8 HIGH Integer overflow in dynamic kernel object allocation allows user-mode threads to corrupt t
CVE-2026-19574 7.0 HIGH ARM64 MMU can assign an in-use ASID to a new memory domain, breaking user-mode memory isol
CVE-2026-19571 6.7 MEDIUM Race condition in ITE IT8xxx2 SHI host-command backend lets a second SPI request write an

IV. Related Vulnerabilities

V. Comments for CVE-2026-19575

No comments yet


Leave a comment