---
id: CVE-2026-19185
title: >-
  The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c
  validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and
  the targets.payloads[] array, but did not validate the per-target data buffers
  those ar…
summary: >-
  The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c
  validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and
  the targets.payloads[] array, but did not validate the per-target data buffers
  those ar…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-822
vendor: zephyrproject
product: zephyr
affected:
  - zephyr >= 3.2.0 < 4.5.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T09:17:13.077'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19185'
references:
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/commit/35562f22f40c6d2f31969a31f0a4902e5b067f27
    label: vulnerabilities@zephyrproject.org
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-pcrr-29j7-8w57
    label: vulnerabilities@zephyrproject.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T09:16:17.877Z'
---

## Overview

The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data pointer and data_len, and neither was passed through K_SYSCALL_MEMORY() before the payload was handed to z_impl_i3c_do_ccc() and on to the controller driver. The verifier also operated on the caller's live structure rather than a snapshot, so validated fields could be changed by a second user thread between the check and the driver's use — unlike the sibling z_vrfy_i3c_transfer(), which has always copied its message array first.

The defect is only present in CONFIG_USERSPACE builds, where drivers/i3c/i3c_handlers.c is compiled. An unprivileged user-mode thread that has been granted access to the I3C controller device object — the ordinary way an application lets a user thread talk to I3C peripherals — can issue a direct CCC whose target payload data pointer names an arbitrary kernel address. Controller drivers dereference that pointer directly (for example drivers/i3c/i3c_mcux.c, drivers/i3c/i3c_cdns.c, drivers/i3c/i3c_stm32.c, drivers/i3c/i3c_npcx.c), using rnw to decide direction.

A read CCC therefore causes the kernel-mode driver to write bus-received bytes into an attacker-chosen kernel address for an attacker-chosen length, and a write CCC transmits kernel memory out onto the I3C bus. The result is an out-of-bounds kernel write plus a kernel memory disclosure, i.e. escalation from a user-mode thread to supervisor privilege, defeating the isolation CONFIG_USERSPACE is meant to provide.

The fix introduces copy_ccc_and_do(), which snapshots the payload, copies the target array into kernel memory with k_usermode_alloc_from_copy() (bounding num_targets to fewer than 32), validates each per-target buffer with K_SYSCALL_MEMORY() according to rnw, and copies the driver-written num_xfer and err fields back to the caller.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
