Junglewise Threat Intelligence

CVE-2026-9771: Zephyr RTOS flash_copy() privilege escalation via unvalidated device pointers

CVE-2026-9771 · Severity: high · CVSS 8.8 · Published 2026-08-17

Technologies: Zephyr Project Zephyr RTOS. Vendors: Zephyr Project.

Executive brief

Zephyr RTOS is a lightweight operating system used in embedded and IoT devices. A flaw in the flash_copy() system call allows unprivileged user-mode code to call kernel functions with arbitrary parameters, enabling local privilege escalation and potential kernel compromise. An attacker with basic user access could gain supervisor-level control or crash the device entirely.

Technical details

The vulnerability is a privilege escalation flaw in the flash_copy() syscall handler (z_vrfy_flash_copy() in drivers/flash/flash_util.c) affecting Zephyr RTOS builds with CONFIG_USERSPACE enabled. The handler validates only the output buffer but fails to validate the src_dev and dst_dev device pointers before passing them to the implementation (z_impl_flash_copy()), which dereferences them and invokes function pointers from their driver API tables. An unprivileged user-mode thread can supply a forged struct device with a malicious API function table, causing the kernel to execute arbitrary code in supervisor mode. The attack requires only user-level code execution and local access. The fix adds K_SYSCALL_DRIVER_FLASH validation macros to verify both device pointers are registered flash-driver kernel objects before use.

Affected products

  • Zephyr Project Zephyr RTOS prior to fix (CONFIG_USERSPACE builds)

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: advisory

Related threats