Skip to main content

CVE-2026-17053: auth in zephyrproject zephyr

0
Medium
VulnerabilityCVE-2026-17053cvecve-2026-17053
Published: 10/01/2026 (10/01/2026, 15:08:52 UTC)
Source: CVE Database V5
Vendor/Project: zephyrproject
Product: zephyr

Description

The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded the caller-supplied struct smbus_callback *cb pointer into kernel-mode driver code without any K_SYSCALL_MEMORY_READ/K_SYSCALL_MEMORY_WRITE validation. A companion change in 2023 had already removed the matching smbus_smbalert_set_cb() / smbus_host_notify_set_cb() syscalls for this reason, but the two removal syscalls were left exposed. On a build with CONFIG_USERSPACE=y, CONFIG_SMBUS=y and a driver implementing the callback operations (drivers/smbus/intel_pch_smbus.c with CONFIG_SMBUS_INTEL_PCH_SMBALERT/CONFIG_SMBUS_INTEL_PCH_HOST_NOTIFY, or drivers/smbus/smbus_stm32.c with CONFIG_SMBUS_STM32_SMBALERT), any user-mode thread that has been granted the SMBus device object can invoke these syscalls with an arbitrary pointer. The value reaches smbus_callback_remove() in drivers/smbus/smbus_utils.h, which uses it as a node identity against the kernel's sys_slist_t of registered callbacks. The consequence is that an unprivileged thread can unregister an SMBALERT or Host Notify callback that a supervisor-mode component registered, silently disabling alert handling for the rest of the system; because Zephyr images have fixed symbol addresses and the syscall returns 0 on a hit versus -ENOENT on a miss, the target address is both derivable and searchable. In builds with CONFIG_ASSERT=y the __ASSERT(callback->handler, ...) check additionally dereferences the caller-supplied address in supervisor mode, so a bogus pointer raises a kernel-mode fault and a fatal system error, and the fault/no-fault outcome discloses which addresses are mapped. The fix removes both syscall entry points, demoting the two functions to ordinary static inline calls so that callback list manipulation is available only to supervisor-mode code. There is no impact on builds without CONFIG_USERSPACE, and no impact on configurations that do not enable an SMBus driver with SMBALERT or Host Notify support.

CVSS v3.1

Score 4.4medium

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

Affected software

zephyrproject

zephyr

Affected versions
>=3.4.0 <4.4.2
GitHub Actionsmore threats →cve
zephyr
pkg:github/zephyr
Affected versions
>=3.4.0 <4.4.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/01/2026, 15:46:08 UTC

Technical Analysis

The vulnerability arises from the SMBus driver API exposing smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls that validate only the device argument but not the user-supplied callback pointer. This pointer is used directly in kernel-mode callback list manipulation, allowing unprivileged user-mode threads with SMBus device access to unregister callbacks registered by supervisor-mode components. This can silently disable SMBALERT or Host Notify callbacks system-wide or cause kernel faults that reveal mapped addresses. The fix removes these syscalls, making the functions static inline and accessible only to supervisor-mode code. The vulnerability affects Zephyr versions from 3.4.0 up to but not including 4.4.2, only when user-space and SMBus drivers with SMBALERT or Host Notify support are enabled.

Potential Impact

An unprivileged user-mode thread with SMBus device access can unregister critical SMBALERT or Host Notify callbacks registered by supervisor-mode components, disabling alert handling for the system. Additionally, in builds with assertions enabled, supplying bogus pointers can cause kernel faults and fatal system errors, leaking information about mapped kernel addresses. This can degrade system reliability and potentially aid further attacks by revealing memory layout details. There is no impact on builds without user-space or without the affected SMBus drivers.

Mitigation Recommendations

The vulnerability is fixed by removing the two syscall entry points and restricting callback list manipulation to supervisor-mode code only. Users should upgrade to Zephyr version 4.4.2 or later where this fix is included. There is no impact on builds without CONFIG_USERSPACE or without SMBus drivers with SMBALERT or Host Notify support. No additional mitigation is required beyond applying the official fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
zephyr
Date Reserved
2026-07-24T13:31:06.974Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6abe7ce6a43b0b3b89c10b5c

Added to database: 10/01/2026, 15:31:50 UTC

Last enriched: 10/01/2026, 15:46:08 UTC

Last updated: 10/01/2026, 16:31:52 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses