rootpwn

high · CVSS v3 7.8

CVE-2026-18413

A buffer overflow in the NXP MCUX LPADC driver for Zephyr RTOS allows an unprivileged user-mode thread to write beyond the allocated buffer

Overview

A buffer overflow in the NXP MCUX LPADC driver for Zephyr RTOS allows an unprivileged user-mode thread to write beyond the allocated buffer during ADC sampling. The flaw bypasses driver‑level bounds checking, leading to kernel memory corruption. This can be leveraged for privilege escalation or denial‑of‑service on affected Zephyr builds.

Description

The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The NXP MCUX LPADC driver did not honour that contract. mcux_lpadc_start_read() in drivers/adc/adc_mcux_lpadc.c performed no buffer-size check at all before assigning data->buffer = sequence->buffer. Each completed conversion then stores one 16-bit sample per enabled channel per sampling round through an unbounded *data->buffer++: in mcux_lpadc_isr() for interrupt-driven builds, and in mcux_lpadc_dma_callback() for DMA-driven builds on releases that have the DMA path. A sequence selecting two channels with a two-byte buffer, for example, has its second sample written past the end of the buffer. On a build with CONFIG_USERSPACE, adc_read() and adc_read_async() are system calls. The handler in drivers/adc/adc_handlers.c copies the sequence in from user memory, verifies only that [buffer, buffer + buffer_size) is writable by the calling thread, and rejects a user-supplied options->callback; it deliberately leaves the size arithmetic to the driver. A user-mode thread that has been granted access to an LPADC device object therefore fully controls channels, buffer, buffer_size and options->extra_samplings, and can request far more samples than its buffer can hold: up to channels * 65536 samples into a two-byte buffer, since the sample pointer is only rewound on a repeat sampling, never on the extra samplings of a sequence. The resulting stores are performed by the driver in kernel mode (in the ADC interrupt handler or the DMA completion callback), where the MPU does not restrict the thread's memory domain, so the write walks linearly out of the user partition and into adjacent memory such as other partitions, kernel data or thread stacks. The impact is kernel-memory corruption of attacker-chosen length at an attacker-chosen offset, a plausible privilege-escalation and denial-of-service primitive from an unprivileged user-mode thread. Builds without CONFIG_USERSPACE are affected only as a caller-side robustness defect, since the application itself supplies the buffer. The fix calls the new shared helper adc_sequence_validate_buffer() in drivers/adc/adc_common.c from mcux_lpadc_start_read(). The helper computes active_channels sizeof(uint16_t) (1 + extra_samplings) and returns -ENOMEM before any sampling is started.

Impact

The vulnerability corrupts kernel memory, compromising integrity and availability of the system. Confidentiality is at risk if attacker writes sensitive data. Unprivileged user threads on Zephyr devices using the MCUX LPADC driver are the primary impact group.

Remediation

Update to a Zephyr release that includes the adc_sequence_validate_buffer() fix, or manually apply the patch to drivers/adc/adc_mcux_lpadc.c. Disable CONFIG_USERSPACE if not needed, or restrict ADC access to privileged threads only. Verify buffer sizes and channel counts before initiating ADC reads.

Risk context

Severity is high with a CVSS v3 score of 7.8. No EPSS data is available, but the flaw remains exploitable in current releases, warranting prompt mitigation.

Affected products

  • NXP MCUX LPADC
  • Zephyr RTOS ADC API

Scores

Severity
high
CVSS v2
6.8
CVSS v3
7.8
CVSS v4
—
EPSS
—

buffer-overflow kernel-corruption privilege-escalation Zephyr NXP ADC CONFIG_USERSPACE

← All CVEs