CVE-2026-17053: auth in zephyrproject zephyr
The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded the caller-supplied struct smbus_callback *cb pointer into kernel-mode driver code without any K_SYSCALL_MEMORY_READ/K_SYSCALL_MEMORY_WRITE validation. A companion change in 2023 had already removed the matching smbus_smbalert_set_cb() / smbus_host_notify_set_cb() syscalls for this reason, but the two removal syscalls were left exposed. On a build with CONFIG_USERSPACE=y, CONFIG_SMBUS=y and a driver implementing the callback operations (drivers/smbus/intel_pch_smbus.c with CONFIG_SMBUS_INTEL_PCH_SMBALERT/CONFIG_SMBUS_INTEL_PCH_HOST_NOTIFY, or drivers/smbus/smbus_stm32.c with CONFIG_SMBUS_STM32_SMBALERT), any user-mode thread that has been granted the SMBus device object can invoke these syscalls with an arbitrary pointer. The value reaches smbus_callback_remove() in drivers/smbus/smbus_utils.h, which uses it as a node identity against the kernel's sys_slist_t of registered callbacks. The consequence is that an unprivileged thread can unregister an SMBALERT or Host Notify callback that a supervisor-mode component registered, silently disabling alert handling for the rest of the system; because Zephyr images have fixed symbol addresses and the syscall returns 0 on a hit versus -ENOENT on a miss, the target address is both derivable and searchable. In builds with CONFIG_ASSERT=y the __ASSERT(callback->handler, ...) check additionally dereferences the caller-supplied address in supervisor mode, so a bogus pointer raises a kernel-mode fault and a fatal system error, and the fault/no-fault outcome discloses which addresses are mapped. The fix removes both syscall entry points, demoting the two functions to ordinary static inline calls so that callback list manipulation is available only to supervisor-mode code. There is no impact on builds without CONFIG_USERSPACE, and no impact on configurations that do not enable an SMBus driver with SMBALERT or Host Notify support.
AI Analysis
Technical Summary
The vulnerability arises from the SMBus driver API exposing smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls that validate only the device argument but not the user-supplied callback pointer. This pointer is used directly in kernel-mode callback list manipulation, allowing unprivileged user-mode threads with SMBus device access to unregister callbacks registered by supervisor-mode components. This can silently disable SMBALERT or Host Notify callbacks system-wide or cause kernel faults that reveal mapped addresses. The fix removes these syscalls, making the functions static inline and accessible only to supervisor-mode code. The vulnerability affects Zephyr versions from 3.4.0 up to but not including 4.4.2, only when user-space and SMBus drivers with SMBALERT or Host Notify support are enabled.
Potential Impact
An unprivileged user-mode thread with SMBus device access can unregister critical SMBALERT or Host Notify callbacks registered by supervisor-mode components, disabling alert handling for the system. Additionally, in builds with assertions enabled, supplying bogus pointers can cause kernel faults and fatal system errors, leaking information about mapped kernel addresses. This can degrade system reliability and potentially aid further attacks by revealing memory layout details. There is no impact on builds without user-space or without the affected SMBus drivers.
Mitigation Recommendations
The vulnerability is fixed by removing the two syscall entry points and restricting callback list manipulation to supervisor-mode code only. Users should upgrade to Zephyr version 4.4.2 or later where this fix is included. There is no impact on builds without CONFIG_USERSPACE or without SMBus drivers with SMBALERT or Host Notify support. No additional mitigation is required beyond applying the official fix.
CVE-2026-17053: auth in zephyrproject zephyr
Description
The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded the caller-supplied struct smbus_callback *cb pointer into kernel-mode driver code without any K_SYSCALL_MEMORY_READ/K_SYSCALL_MEMORY_WRITE validation. A companion change in 2023 had already removed the matching smbus_smbalert_set_cb() / smbus_host_notify_set_cb() syscalls for this reason, but the two removal syscalls were left exposed. On a build with CONFIG_USERSPACE=y, CONFIG_SMBUS=y and a driver implementing the callback operations (drivers/smbus/intel_pch_smbus.c with CONFIG_SMBUS_INTEL_PCH_SMBALERT/CONFIG_SMBUS_INTEL_PCH_HOST_NOTIFY, or drivers/smbus/smbus_stm32.c with CONFIG_SMBUS_STM32_SMBALERT), any user-mode thread that has been granted the SMBus device object can invoke these syscalls with an arbitrary pointer. The value reaches smbus_callback_remove() in drivers/smbus/smbus_utils.h, which uses it as a node identity against the kernel's sys_slist_t of registered callbacks. The consequence is that an unprivileged thread can unregister an SMBALERT or Host Notify callback that a supervisor-mode component registered, silently disabling alert handling for the rest of the system; because Zephyr images have fixed symbol addresses and the syscall returns 0 on a hit versus -ENOENT on a miss, the target address is both derivable and searchable. In builds with CONFIG_ASSERT=y the __ASSERT(callback->handler, ...) check additionally dereferences the caller-supplied address in supervisor mode, so a bogus pointer raises a kernel-mode fault and a fatal system error, and the fault/no-fault outcome discloses which addresses are mapped. The fix removes both syscall entry points, demoting the two functions to ordinary static inline calls so that callback list manipulation is available only to supervisor-mode code. There is no impact on builds without CONFIG_USERSPACE, and no impact on configurations that do not enable an SMBus driver with SMBALERT or Host Notify support.
CVSS v3.1
Score 4.4medium
Affected software
zephyrproject
zephyr
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from the SMBus driver API exposing smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls that validate only the device argument but not the user-supplied callback pointer. This pointer is used directly in kernel-mode callback list manipulation, allowing unprivileged user-mode threads with SMBus device access to unregister callbacks registered by supervisor-mode components. This can silently disable SMBALERT or Host Notify callbacks system-wide or cause kernel faults that reveal mapped addresses. The fix removes these syscalls, making the functions static inline and accessible only to supervisor-mode code. The vulnerability affects Zephyr versions from 3.4.0 up to but not including 4.4.2, only when user-space and SMBus drivers with SMBALERT or Host Notify support are enabled.
Potential Impact
An unprivileged user-mode thread with SMBus device access can unregister critical SMBALERT or Host Notify callbacks registered by supervisor-mode components, disabling alert handling for the system. Additionally, in builds with assertions enabled, supplying bogus pointers can cause kernel faults and fatal system errors, leaking information about mapped kernel addresses. This can degrade system reliability and potentially aid further attacks by revealing memory layout details. There is no impact on builds without user-space or without the affected SMBus drivers.
Mitigation Recommendations
The vulnerability is fixed by removing the two syscall entry points and restricting callback list manipulation to supervisor-mode code only. Users should upgrade to Zephyr version 4.4.2 or later where this fix is included. There is no impact on builds without CONFIG_USERSPACE or without SMBus drivers with SMBALERT or Host Notify support. No additional mitigation is required beyond applying the official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- zephyr
- Date Reserved
- 2026-07-24T13:31:06.974Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abe7ce6a43b0b3b89c10b5c
Added to database: 10/01/2026, 15:31:50 UTC
Last enriched: 10/01/2026, 15:46:08 UTC
Last updated: 10/01/2026, 16:31:52 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.