CVE-2026-13216

Source
https://cve.org/CVERecord?id=CVE-2026-13216
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13216.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-13216
Aliases
  • GHSA-qrh3-4mvv-w667
Published
2026-08-25T16:05:36.964Z
Modified
2026-08-28T14:32:59.484571Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability length
Details

The virtio PCI driver (drivers/virtio/virtiopci.c) parses a device's PCI capability list during driver initialization. In virtiopcireadcap() the device-supplied capability length byte caplen (read from PCI config space via pcieconfread()) was only checked with assert(tmp.caplen == capstructsize). That assert resolves to _ASSERTNOMSG(), gated by CONFIGASSERT, which defaults off in production builds, so the value reached the copy logic completely unvalidated.

The length then drives a loop that copies extra capability dwords into a fixed-size stack buffer supplied by the caller. A caplen below the 24-byte base struct virtiopcicap underflows the unsigned extradatawords count to a near-SIZEMAX value, producing an effectively unbounded stack write; a cap_len above the caller's buffer (up to 255) writes up to roughly 228 bytes of device-controlled data past the buffer. Both are out-of-bounds writes of attacker-controlled content executed in kernel mode during boot-time device probe.

The input originates from the virtio device. In the common deployment where Zephyr runs as a guest under a hypervisor, the device backend is the host, which already fully outranks the guest, so the bug yields no privilege escalation. The exploitable case is a virtio device that is untrusted relative to the Zephyr kernel — an untrusted or physical/passthrough virtio PCIe device on a bare-metal system, or a confidential-computing posture where the guest must defend against the host — where a malicious device can corrupt the kernel stack and potentially achieve code execution or a crash.

The fix replaces the compiled-out assert with a runtime range check rejecting caplen outside [sizeof(struct virtiopcicap), capstruct_size] before any arithmetic or copy.

Database specific
{
    "cna_assigner": "zephyr",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13216.json",
    "cwe_ids": [
        "CWE-787"
    ]
}
References

Affected packages

Git / github.com/zephyrproject-rtos/zephyr

Affected ranges

Type
GIT
Repo
https://github.com/zephyrproject-rtos/zephyr
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "4.2.0"
        },
        {
            "fixed": "4.4.2"
        }
    ]
}

Affected versions

v4.*
v4.2.0
v4.3.0
v4.3.0-rc1
v4.3.0-rc2
v4.3.0-rc3
v4.4.0
v4.4.0-rc1
v4.4.0-rc2
v4.4.0-rc3

Database specific

vanir_signatures
[
    {
        "id": "CVE-2026-13216-61325f8a",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/d98dacee24ad10c972d3b7281c9009d82ed351c9",
        "signature_type": "Function",
        "target": {
            "file": "drivers/virtio/virtio_pci.c",
            "function": "virtio_pci_read_cap"
        },
        "digest": {
            "function_hash": "1237186707346695444725577549462722868",
            "length": 1081.0
        },
        "signature_version": "v1",
        "deprecated": false
    },
    {
        "id": "CVE-2026-13216-6fc94899",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/d98dacee24ad10c972d3b7281c9009d82ed351c9",
        "signature_type": "Line",
        "target": {
            "file": "drivers/virtio/virtio_pci.c"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "141705835514119104656776053557615128448",
                "220439857227802623790854166360684433939",
                "139873091864490449370155597078729568678",
                "191135874435819231484805636579762432338"
            ]
        },
        "signature_version": "v1",
        "deprecated": false
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13216.json"
vanir_signatures_modified
"2026-08-28T14:32:59Z"