PatchSiren cyber security CVE debrief
CVE-2026-19669 zephyrproject CVE debrief
A vulnerability in Zephyr's fuel gauge syscall verifiers allows a kernel stack overflow from user mode, enabling an attacker to execute arbitrary code with elevated privileges. This issue arises from the use of unbounded variable-length arrays in the verifiers, which can be exploited by an attacker with user-mode access. Defenders responsible for Zephyr-based systems, particularly those with CONFIG_USERSPACE enabled, should assess exposure and verify that their systems are running a version of Zephyr that has the fix applied.
- Vendor
- zephyrproject
- Product
- zephyr
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Zephyr-based systems, particularly those with CONFIG_USERSPACE enabled, should assess exposure and verify that their systems are running a version of Zephyr that has the fix applied.
Why it matters
A vulnerability in Zephyr's fuel gauge syscall verifiers allows a kernel stack overflow from user mode, enabling an attacker to execute arbitrary code with elevated privileges. Defenders responsible for Zephyr-based systems, particularly those with CONFIG_USERSPACE enabled, should assess exposure and verify that their systems are running a version of Zephyr that has the fix applied.
- Potential kernel stack overflow and arbitrary code execution with elevated privileges
- Possible disruption of system operations
- Need for verification of system configuration and patch application
- Potential for exploitation by an attacker with user-mode access
Technical summary
The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_props[len], sized directly by the caller-supplied len argument. len is an unvalidated size_t taken straight from the syscall ABI, and the VLAs were allocated before any check at all — including before the K_SYSCALL_DRIVER_FUEL_GAUGE() object-permission check.
Defensive priority
High
Recommended defensive actions
- Review and apply the patch provided by the vendor
- Verify that the system is running a version of Zephyr that has the fix applied
- Monitor system logs for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability is caused by the use of unbounded variable-length arrays in the fuel gauge syscall verifiers, which can lead to a kernel stack overflow. The CVE record and source item also provide information on the affected versions and the fix applied to address the issue. To verify the fix, defenders should review the patch provided by the vendor and apply it to their systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19669 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19669
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19669 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19669
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Unbounded variable-length array in fuel gauge syscall verifiers allows kernel stack overflow fro
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/19xxx/CVE-2026-19669.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/commit/0d65ce46dda0626164503c50f37e6e1f59d310a9
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-6ghg-cmrw-8gw5
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.