The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data pointer and data_len, and neither was passed through K_SYSCALL_MEMORY() before the payload was handed to z_impl_i3c_do_ccc() and on to the controller driver. The verifier also operated on the caller's live structure rather than a snapshot, so validated fields could be changed by a second user thread between the check and the driver's use — unlike the sibling z_vrfy_i3c_transfer(), which has always copied its message array first.
The defect is only present in CONFIG_USERSPACE builds, where drivers/i3c/i3c_handlers.c is compiled. An unprivileged user-mode thread that has been granted access to the I3C controller device object — the ordinary way an application lets a user thread talk to I3C peripherals — can issue a direct CCC whose target payload data pointer names an arbitrary kernel address. Controller drivers dereference that pointer directly (for example drivers/i3c/i3c_mcux.c, drivers/i3c/i3c_cdns.c, drivers/i3c/i3c_stm32.c, drivers/i3c/i3c_npcx.c), using rnw to decide direction.
A read CCC therefore causes the kernel-mode driver to write bus-received bytes into an attacker-chosen kernel address for an attacker-chosen length, and a write CCC transmits kernel memory out onto the I3C bus. The result is an out-of-bounds kernel write plus a kernel memory disclosure, i.e. escalation from a user-mode thread to supervisor privilege, defeating the isolation CONFIG_USERSPACE is meant to provide.
The fix introduces copy_ccc_and_do(), which snapshots the payload, copies the target array into kernel memory with k_usermode_alloc_from_copy() (bounding num_targets to fewer than 32), validates each per-target buffer with K_SYSCALL_MEMORY() according to rnw, and copies the driver-written num_xfer and err fields back to the caller.
{
"cna_assigner": "zephyr",
"cwe_ids": [
"CWE-822"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19185.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "3.2.0"
},
{
"fixed": "4.5.0"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19185.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"321535828567680787554379738995839115908",
"280582362550889913193311602800052884802",
"15184777578877487774329648994437988736",
"115473687681671949237033815573479258482",
"104604730085248019064104102542764781087",
"6514681875452727521427203427616394612",
"196209970136846863960977452272628491435",
"156793658510666950889053361112561562703",
"93156357190652097964523879618745416499",
"102501617329479409650172186320025061949",
"4941269537114831812732658339173183011",
"106789627815767948725581617194389508156",
"25374937631769929677049904574227334947",
"88329854855325680197283899458988215275",
"22913943274906961316050392427893668681",
"167460227898560766967901278943900757634",
"313186492629835660141883734572670344880",
"207244602896687238395962786440161924314",
"305153978446090133387520607480637594138",
"111098558523868809827762262884465497184",
"194659768465967495134845089498138288189",
"283954784136840844613539163259812625058",
"126010445155989380830404819112456625782"
],
"threshold": 0.9
},
"id": "CVE-2026-19185-176ac323",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/35562f22f40c6d2f31969a31f0a4902e5b067f27",
"target": {
"file": "drivers/i3c/i3c_handlers.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "258586291440076280812203974113332279232",
"length": 829
},
"id": "CVE-2026-19185-bf7f7c86",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/35562f22f40c6d2f31969a31f0a4902e5b067f27",
"target": {
"file": "drivers/i3c/i3c_handlers.c",
"function": "z_vrfy_i3c_do_ccc"
}
}
]
"2026-10-08T07:09:19Z"