CVE-2026-18413: Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer size validation
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffersize field of struct adcsequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The NXP MCUX LPADC driver did not honour that contract. mcuxlpadcstartread() in drivers/adc/adcmcuxlpadc.c performed no buffer-size check at all before assigning data->buffer = sequence->buffer. Each completed conversion then stores one 16-bit sample per enabled channel per sampling round through an unbounded data->buffer++: in mcuxlpadcisr() for interrupt-driven builds, and in mcuxlpadcdmacallback() for DMA-driven builds on releases that have the DMA path. A sequence selecting two channels with a two-byte buffer, for example, has its second sample written past the end of the buffer.
On a build with CONFIGUSERSPACE, adcread() and adcreadasync() are system calls. The handler in drivers/adc/adchandlers.c copies the sequence in from user memory, verifies only that [buffer, buffer + buffersize) is writable by the calling thread, and rejects a user-supplied options->callback; it deliberately leaves the size arithmetic to the driver. A user-mode thread that has been granted access to an LPADC device object therefore fully controls channels, buffer, buffersize and options->extrasamplings, and can request far more samples than its buffer can hold: up to channels 65536 samples into a two-byte buffer, since the sample pointer is only rewound on a repeat sampling, never on the extra samplings of a sequence.
The resulting stores are performed by the driver in kernel mode (in the ADC interrupt handler or the DMA completion callback), where the MPU does not restrict the thread's memory domain, so the write walks linearly out of the user partition and into adjacent memory such as other partitions, kernel data or thread stacks. The impact is kernel-memory corruption of attacker-chosen length at an attacker-chosen offset, a plausible privilege-escalation and denial-of-service primitive from an unprivileged user-mode thread. Builds without CONFIGUSERSPACE are affected only as a caller-side robustness defect, since the application itself supplies the buffer.
The fix calls the new shared helper adcsequencevalidatebuffer() in drivers/adc/adccommon.c from mcuxlpadcstartread(). The helper computes activechannels sizeof(uint16t) (1 + extrasamplings) and returns -ENOMEM before any sampling is started.
Affected Software
Event History
Frequently Asked Questions
Who can trigger the overwrite?
An attacker needs local, low-privilege access and the ability to invoke the LPADC driver's read path with a crafted sampling sequence. In CONFIG_USERSPACE builds, adc_read() and adc_read_async() are system calls, and the syscall handler checks that the supplied buffer range is writable but does not establish that it is large enough for all requested samples.
What makes a sampling sequence unsafe?
A sequence is unsafe when its destination buffer cannot hold one 16-bit sample for every enabled channel in every sampling round. For example, selecting two channels while providing a two-byte buffer causes the second sample to be written beyond the buffer.
Is this limited to DMA-enabled systems?
No. Interrupt-driven builds write samples through an unbounded buffer increment in mcux_lpadc_isr(), while DMA-enabled builds with the DMA path write through the corresponding unbounded handling in mcux_lpadc_dma_callback().