CVE-2026-18909: Buffer Overflow
A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVEROVERRANSTACKBUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ELAN Smart-Pad (ETD.sys and ETDSMBus.sys)to a version that resolves this vulnerability.Fixed in ETD24.21.53.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18909?
The severity of CVE-2026-18909 is medium, with a score of 4.7.
What causes CVE-2026-18909?
CVE-2026-18909 is caused by a stack-based buffer overflow in the ELAN Smart-Pad drivers during the Intel SMBus recovery process.
How do I fix CVE-2026-18909?
To fix CVE-2026-18909, update to the latest version of the ELAN Smart-Pad software that addresses the buffer overflow vulnerability.
What are the potential impacts of CVE-2026-18909?
CVE-2026-18909 may lead to denial of service due to the buffer overflow and affects the system's stability.
Which systems are affected by CVE-2026-18909?
CVE-2026-18909 affects systems running ELAN Microelectronics Corp. ELAN Smart-Pad drivers on Windows.