Junglewise Threat Intelligence

CVE-2026-10679: Zephyr OS divide by zero in DesignWare SPI driver

CVE-2026-10679 · Severity: low · CVSS 3.3 · Published 2026-07-21

Technologies: Zephyr Project Zephyr OS. Vendors: Zephyr Project.

Executive brief

Zephyr is an open-source operating system designed for resource-constrained embedded devices. A flaw in the DesignWare SPI driver allows a local user or application with specific hardware permissions to crash the system by providing an invalid frequency value. This results in a system-wide restart or freeze, causing a denial of service, though it does not allow for data theft or unauthorized access.

Technical details

A divide-by-zero vulnerability (CWE-369) exists in the DesignWare SPI driver (`drivers/spi/spi_dw.c`) within Zephyr OS. The `spi_transceive` syscall handler fails to validate the `frequency` field of the `spi_config` structure copied from userspace. When `frequency` is set to zero, the `SPI_DW_CLK_DIVIDER` macro performs an unsigned integer division by zero during hardware configuration. On architectures like ARM Cortex-M and ARC, this triggers a CPU exception and kernel fault. Exploitation requires `CONFIG_USERSPACE=y` and the calling thread must have been granted permission to the SPI device kernel object. The issue is fixed in version 4.5.0 by rejecting zero frequencies and those exceeding half the input clock frequency.

Affected products

  • Zephyr Project Zephyr OS >= 1.8.0, <= 4.4.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory
  • 2026-07-21: patched

References

Related threats