{"id":"CVE-2026-19569","summary":"Integer overflow in dynamic kernel object allocation allows user-mode threads to corrupt the kernel heap","details":"dynamic_object_create() in kernel/userspace/userspace.c computed the backing allocation for a dynamically allocated kernel object as obj_size_get(otype) + size, and for thread stack elements as STACK_ELEMENT_DATA_SIZE(size) (a round-up plus fixed overhead), without checking either expression for unsigned wrap-around. A size close to SIZE_MAX makes the computed total wrap to a very small value, so the heap chunk handed out is a few bytes while the object descriptor is still tagged with the full requested type and registered in the kernel object table.\n\nThe size argument reaches that arithmetic directly from user mode. k_object_alloc_size() is declared __syscall in include/zephyr/sys/kobject.h, its verifier z_vrfy_k_object_alloc_size() in kernel/userspace/userspace_handler.c is a bare pass-through, and z_object_alloc() only range-checks otype — nothing bounds size. The stack-element branch is additionally reachable through the k_thread_stack_alloc() syscall via kernel/dynamic.c. Because subsequent kernel-object validation checks only the object's type and initialization state, the undersized handle passes K_SYSCALL_OBJ_INIT()/K_SYSCALL_OBJ_NEVER_INIT(), and the matching init syscall (for example k_mutex_init(), k_sem_init(), or k_thread_create()) then writes a complete object over the truncated allocation.\n\nAn unprivileged user-mode thread can therefore trigger a supervisor-mode out-of-bounds write into the kernel resource-pool heap, of a size and content it substantially controls, corrupting sys_heap chunk metadata and adjacent kernel objects. Under CONFIG_GEN_PRIV_STACKS the thread-stack branch additionally stores an attacker-influenced wild pointer as a user thread's privileged stack base. The practical result is escape from the CONFIG_USERSPACE sandbox — kernel-level code execution or at minimum kernel memory corruption and system compromise.\n\nExploitation requires CONFIG_USERSPACE together with CONFIG_DYNAMIC_OBJECTS (also selected by CONFIG_DYNAMIC_THREAD under userspace), and a calling thread with an assigned resource pool. The fix rejects both overflowing computations and frees the partially built descriptor.","aliases":["GHSA-fg8c-9fhq-q7hv"],"modified":"2026-10-11T07:04:33.716420720Z","published":"2026-10-09T07:16:45.305Z","database_specific":{"cna_assigner":"zephyr","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19569.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19569.json"},{"type":"ADVISORY","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fg8c-9fhq-q7hv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19569"},{"type":"FIX","url":"https://github.com/zephyrproject-rtos/zephyr/commit/85c1c4c21945d9b8fcef03216f1ccb2b27794e3d"},{"type":"PACKAGE","url":"https://github.com/zephyrproject-rtos/zephyr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zephyrproject-rtos/zephyr","events":[{"introduced":"a6eef0ba3755f2530c5ce93524e5ac4f5be30194"},{"fixed":"85c1c4c21945d9b8fcef03216f1ccb2b27794e3d"}],"database_specific":{"extracted_events":[{"introduced":"3.5.0"},{"last_affected":"4.4.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v4.4.0","v4.4.0-rc3","v4.4.0-rc2","v4.4.0-rc1","v4.3.0","v4.3.0-rc3","v4.3.0-rc2","v4.3.0-rc1","v4.2.0","v4.2.0-rc3","v4.2.0-rc2","v4.2.0-rc1","v4.1.0","v4.1.0-rc3","v4.1.0-rc2","v4.1.0-rc1","v4.0.0","v4.0.0-rc3","v4.0.0-rc2","v4.0.0-rc1","v3.7.0","v3.7.0-rc3","v3.7.0-rc2","v3.7.0-rc1","v3.6.0","v3.6.0-rc3","v3.6.0-rc2","v3.6.0-rc1","zephyr-v3.5.0","v3.5.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["36454268777023345026521278940320092697","118259757402433086376212343279145764950","200772270681841406992325068978830828434","11000795259177925124742583135061676929","296255558466555715982954338599839408644","7871248873745594926467037921441743851","333048159683937008201797999119664584658","96498025971983835996669512523013333446"],"threshold":0.9},"id":"CVE-2026-19569-bd96291c","signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/85c1c4c21945d9b8fcef03216f1ccb2b27794e3d","target":{"file":"kernel/userspace/userspace.c"}},{"target":{"file":"kernel/userspace/userspace.c","function":"dynamic_object_create"},"deprecated":false,"digest":{"length":1688,"function_hash":"147705173659567252538042352490506451847"},"id":"CVE-2026-19569-eea37506","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/85c1c4c21945d9b8fcef03216f1ccb2b27794e3d"}],"vanir_signatures_modified":"2026-10-11T07:04:33Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19569.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}