Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Alto CVE-2026-19185 Multiple Vendors

Vulnerabilidad alta en controlador i3c afecta validación de memoria del sistema

Vulnerabilidad · Publicado 05/10/2026

7.8
CVSS 3.x
04 Medio7 Alto9 Crítico10
Severidad: Alto
Resumen ejecutivo

Se ha identificado una vulnerabilidad en el verificador de llamadas al sistema para i3c_do_ccc() en drivers/i3c/i3c_handlers.c que no valida correctamente los búferes de datos por destino en la estructura i3c_ccc_target_payload. Un atacante local podría explotar esta deficiencia para acceder o modificar memoria del kernel, afectando sistemas embebidos e IoT industriales comúnmente desplegados en infraestructura alta de LATAM.

Análisis asistido por IA, contexto LATAM revisado por el equipo 2MCI.

Descripción técnica

Descripción técnica

The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data pointer and data_len, and neither was passed through K_SYSCALL_MEMORY() before the payload was handed to z_impl_i3c_do_ccc() and on to the controller driver. The verifier also operated on the caller's live structure rather than a snapshot, so validated fields could be changed by a second user thread between the check and the driver's use — unlike the sibling z_vrfy_i3c_transfer(), which has always copied its message array first. The defect is only present in CONFIG_USERSPACE builds, where drivers/i3c/i3c_handlers.c is compiled. An unprivileged user-mode thread that has been granted access to the I3C controller device object — the ordinary way an application lets a user thread talk to I3C peripherals — can issue a direct CCC whose target payload data pointer names an arbitrary kernel address. Controller drivers dereference that pointer directly (for example drivers/i3c/i3c_mcux.c, drivers/i3c/i3c_cdns.c, drivers/i3c/i3c_stm32.c, drivers/i3c/i3c_npcx.c), using rnw to decide direction. A read CCC therefore causes the kernel-mode driver to write bus-received bytes into an attacker-chosen kernel address for an attacker-chosen length, and a write CCC transmits kernel memory out onto the I3C bus. The result is an out-of-bounds kernel write plus a kernel memory disclosure, i.e. escalation from a user-mode thread to supervisor privilege, defeating the isolation CONFIG_USERSPACE is meant to provide. The fix introduces copy_ccc_and_do(), which snapshots the payload, copies the target array into kernel memory with k_usermode_alloc_from_copy() (bounding num_targets to fewer than 32), validates each per-target buffer with K_SYSCALL_MEMORY() according to rnw, and copies the driver-written num_xfer and err fields back to the caller.

Puntuación CVSS

Score: 7.8/10 — Severidad: HIGH — Estado NIST: Received

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Debilidades (CWE)

CWE-822

Fuente oficial

Publicado en NIST NVD.

¿Qué hacer?
  • Inventariar dispositivos con drivers i3c activos (principalmente sistemas embebidos y controladores industriales)
  • Aplicar parches del fabricante inmediatamente cuando estén disponibles
  • Implementar restricciones de acceso a nivel de usuario para limitar llamadas al sistema i3c_do_ccc()
  • Monitorear NIST NVD y advisories del fabricante para actualizaciones de estado del CVE-2026-19185
  • Evaluar impacto según CVSS 7.8 y criticidad operacional de los sistemas afectados
Esta alerta fue generada automáticamente a partir del NVD del NIST.