{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-18418", "assignerOrgId": "e2e69745-5e70-4e92-8431-deb5529a81ad", "state": "PUBLISHED", "assignerShortName": "zephyr", "dateReserved": "2026-07-30T17:54:15.055Z", "datePublished": "2026-10-11T17:15:00.221Z", "dateUpdated": "2026-10-11T17:15:00.221Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "e2e69745-5e70-4e92-8431-deb5529a81ad", "shortName": "zephyr", "dateUpdated": "2026-10-11T17:15:00.221Z" }, "title": "Out-of-bounds read when the zbus proxy agent IPC backend logs a rejected peer frame's channel name", "descriptions": [ { "lang": "en", "value": "The zbus proxy agent IPC backend in subsys/zbus/proxy_agent/zbus_proxy_agent_ipc.c logged the channel name of a rejected inter-domain frame with a plain %s conversion. The frame type struct zbus_proxy_msg carries a fixed-size channel_name[] array as its last member, and nothing in the transport guarantees the array is NUL-terminated. The only code that verifies termination is zbus_proxy_agent_receive_cb() in subsys/zbus/proxy_agent/zbus_proxy_agent.c, which rejects the frame in precisely those cases — so the warning printed a non-terminated buffer exactly on the error paths where the name had been found invalid (or, for an invalid message_size, had not been inspected at all).\n\nAny peer domain able to place a frame of sizeof(struct zbus_proxy_msg) bytes on the bound ipc_service endpoint can trigger it, by sending a frame with an out-of-range message_size or with channel_name[] containing no NUL byte. Reaching the code requires CONFIG_ZBUS_PROXY_AGENT_IPC and logging built at warning level or above (the default), and requires control over the firmware of the peer domain — typically a second core on the same SoC.\n\nThe resulting strlen() inside the log packager walks past the end of the frame object until it finds a zero byte. With the icmsg backend the frame lives in a stack buffer of the IPC work-queue thread, so bytes of that thread's stack are rendered into the log message; with the rpmsg backends the scan continues through the shared vring memory. Impact is bounded to disclosure of a small amount of adjacent memory into the receiving domain's log sink, plus a possible fatal fault if the scan leaves a mapped region; the log packager's own -ENOSPC bound prevents the overrun from becoming a write. The fix bounds the conversion with %.*s and MIN(msg->channel_name_len, sizeof(msg->channel_name))." } ], "affected": [ { "vendor": "zephyrproject", "product": "zephyr", "collectionURL": "https://github.com/zephyrproject-rtos/zephyr", "packageName": "zephyr", "defaultStatus": "unaffected", "programFiles": [ "subsys/zbus/proxy_agent/zbus_proxy_agent_ipc.c" ], "programRoutines": [ { "name": "zbus_proxy_agent_ipc_recv_callback" } ], "versions": [ { "version": "4.4.0", "status": "affected", "versionType": "semver", "lessThan": "4.4.2" } ] } ], "references": [ { "url": "https://github.com/zephyrproject-rtos/zephyr/commit/fc065f79a568a6c6cc14b89795bd60e5eabd6f02", "name": "Fix commit", "tags": [ "patch" ] }, { "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-48w8-fjhj-r9w8", "name": "GHSA-48w8-fjhj-r9w8" } ], "metrics": [ { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:L", "baseScore": 3.4, "baseSeverity": "LOW" } } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "bounds", "cweId": "CWE-125", "type": "CWE" } ] } ], "x_generator": { "engine": "cvelib 1.8.0" } } } }