Executive brief
A vulnerability in the Automotive Grade Linux (AGL) application framework allows attackers to gain full control over the system by installing a malicious widget. The framework fails to properly check the contents of application packages, allowing files to be written to sensitive system locations even if the package's security signature is invalid. This can lead to permanent system compromise, data theft, or complete loss of operational control over the vehicle's software environment.
Technical details
The vulnerability exists in the widget installation flow of AGL's app-framework-main. The 'is_valid_filename' function in 'wgtpkg-zip.c' fails to validate dot-notation directory traversal sequences (../), only blocking absolute paths. During extraction, the 'zread' function uses 'openat' with these unsanitized paths, allowing files to be written outside the intended work directory. Furthermore, a Time-of-Check Time-of-Use (TOCTOU) flaw exists because extraction occurs before signature verification in 'install_widget'. Even if signature verification subsequently fails, the cleanup process only removes the temporary work directory, leaving files written via path traversal permanently on the filesystem. This allows an unauthenticated attacker to achieve arbitrary file write and remote code execution (RCE).
Affected products
- Automotive Grade Linux (AGL) app-framework-main thru 17.1.12
Timeline
- 2026-04-30: disclosed: Disclosed by Innora Security Research
- 2026-05-01: advisory: CVE-2026-37531 published