CVE-2026-19569

Source
https://cve.org/CVERecord?id=CVE-2026-19569
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19569.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19569
Aliases
  • GHSA-fg8c-9fhq-q7hv
Published
2026-10-09T07:16:45Z
Modified
2026-10-11T07:04:33Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Integer overflow in dynamic kernel object allocation allows user-mode threads to corrupt the kernel heap
Details

dynamic_object_create() in kernel/userspace/userspace.c computed the backing allocation for a dynamically allocated kernel object as obj_size_get(otype) + size, and for thread stack elements as STACK_ELEMENT_DATA_SIZE(size) (a round-up plus fixed overhead), without checking either expression for unsigned wrap-around. A size close to SIZE_MAX makes the computed total wrap to a very small value, so the heap chunk handed out is a few bytes while the object descriptor is still tagged with the full requested type and registered in the kernel object table.

The size argument reaches that arithmetic directly from user mode. k_object_alloc_size() is declared __syscall in include/zephyr/sys/kobject.h, its verifier z_vrfy_k_object_alloc_size() in kernel/userspace/userspace_handler.c is a bare pass-through, and z_object_alloc() only range-checks otype — nothing bounds size. The stack-element branch is additionally reachable through the k_thread_stack_alloc() syscall via kernel/dynamic.c. Because subsequent kernel-object validation checks only the object's type and initialization state, the undersized handle passes K_SYSCALL_OBJ_INIT()/K_SYSCALL_OBJ_NEVER_INIT(), and the matching init syscall (for example k_mutex_init(), k_sem_init(), or k_thread_create()) then writes a complete object over the truncated allocation.

An unprivileged user-mode thread can therefore trigger a supervisor-mode out-of-bounds write into the kernel resource-pool heap, of a size and content it substantially controls, corrupting sys_heap chunk metadata and adjacent kernel objects. Under CONFIG_GEN_PRIV_STACKS the thread-stack branch additionally stores an attacker-influenced wild pointer as a user thread's privileged stack base. The practical result is escape from the CONFIG_USERSPACE sandbox — kernel-level code execution or at minimum kernel memory corruption and system compromise.

Exploitation requires CONFIG_USERSPACE together with CONFIG_DYNAMIC_OBJECTS (also selected by CONFIG_DYNAMIC_THREAD under userspace), and a calling thread with an assigned resource pool. The fix rejects both overflowing computations and frees the partially built descriptor.

Database specific
{
    "cna_assigner": "zephyr",
    "cwe_ids": [
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19569.json"
}
References

Affected packages

Git / github.com/zephyrproject-rtos/zephyr

Affected ranges

Type
GIT
Repo
https://github.com/zephyrproject-rtos/zephyr
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.5.0"
        },
        {
            "last_affected": "4.4.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v3.*
v3.5.0
v3.6.0
v3.6.0-rc1
v3.6.0-rc2
v3.6.0-rc3
v3.7.0
v3.7.0-rc1
v3.7.0-rc2
v3.7.0-rc3
v4.*
v4.0.0
v4.0.0-rc1
v4.0.0-rc2
v4.0.0-rc3
v4.1.0
v4.1.0-rc1
v4.1.0-rc2
v4.1.0-rc3
v4.2.0
v4.2.0-rc1
v4.2.0-rc2
v4.2.0-rc3
v4.3.0
v4.3.0-rc1
v4.3.0-rc2
v4.3.0-rc3
v4.4.0
v4.4.0-rc1
v4.4.0-rc2
v4.4.0-rc3
zephyr-v3.*
zephyr-v3.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19569.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "36454268777023345026521278940320092697",
                "118259757402433086376212343279145764950",
                "200772270681841406992325068978830828434",
                "11000795259177925124742583135061676929",
                "296255558466555715982954338599839408644",
                "7871248873745594926467037921441743851",
                "333048159683937008201797999119664584658",
                "96498025971983835996669512523013333446"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-19569-bd96291c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/85c1c4c21945d9b8fcef03216f1ccb2b27794e3d",
        "target": {
            "file": "kernel/userspace/userspace.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "147705173659567252538042352490506451847",
            "length": 1688
        },
        "id": "CVE-2026-19569-eea37506",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/85c1c4c21945d9b8fcef03216f1ccb2b27794e3d",
        "target": {
            "file": "kernel/userspace/userspace.c",
            "function": "dynamic_object_create"
        }
    }
]
vanir_signatures_modified
"2026-10-11T07:04:33Z"