PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19669 zephyrproject CVE debrief

A vulnerability in Zephyr's fuel gauge syscall verifiers allows a kernel stack overflow from user mode, enabling an attacker to execute arbitrary code with elevated privileges. This issue arises from the use of unbounded variable-length arrays in the verifiers, which can be exploited by an attacker with user-mode access. Defenders responsible for Zephyr-based systems, particularly those with CONFIG_USERSPACE enabled, should assess exposure and verify that their systems are running a version of Zephyr that has the fix applied.

Vendor
zephyrproject
Product
zephyr
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for Zephyr-based systems, particularly those with CONFIG_USERSPACE enabled, should assess exposure and verify that their systems are running a version of Zephyr that has the fix applied.

Why it matters

A vulnerability in Zephyr's fuel gauge syscall verifiers allows a kernel stack overflow from user mode, enabling an attacker to execute arbitrary code with elevated privileges. Defenders responsible for Zephyr-based systems, particularly those with CONFIG_USERSPACE enabled, should assess exposure and verify that their systems are running a version of Zephyr that has the fix applied.

  • Potential kernel stack overflow and arbitrary code execution with elevated privileges
  • Possible disruption of system operations
  • Need for verification of system configuration and patch application
  • Potential for exploitation by an attacker with user-mode access

Technical summary

The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_props[len], sized directly by the caller-supplied len argument. len is an unvalidated size_t taken straight from the syscall ABI, and the VLAs were allocated before any check at all — including before the K_SYSCALL_DRIVER_FUEL_GAUGE() object-permission check.

Defensive priority

High

Recommended defensive actions

  • Review and apply the patch provided by the vendor
  • Verify that the system is running a version of Zephyr that has the fix applied
  • Monitor system logs for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability is caused by the use of unbounded variable-length arrays in the fuel gauge syscall verifiers, which can lead to a kernel stack overflow. The CVE record and source item also provide information on the affected versions and the fix applied to address the issue. To verify the fix, defenders should review the patch provided by the vendor and apply it to their systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19669 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19669

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19669 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19669

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.