CVE-2026-19184: Product identification pending
- Severity
- 8.4 (HIGH)
- Vendor
- ZEPHYRPROJECT
- Patch status
- Unknown
- Published
- 2026-10-05T09:17:12.907
- Modified
- 2026-10-05T09:17:12.907
Why it matters
High-severity vulnerability requiring prioritized review.
Recommended admin actions
- Review and patch based on exposure, asset criticality, and business impact.
Technical summary
The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results_length and used it in mcux_gau_adc_read_samples() as the number of uint16_t slots available. Because each conversion result occupies sizeof(uint16_t) bytes, a buffer that was accepted as "large enough" could be written with up to twice its size in bytes, so every sample past the buffer's midpoint was written out of bounds. adc_read() and adc_read_async() are Zephyr system calls. The syscall verifier in drivers/adc/adc_handlers.c only confirms that the caller owns buffer_size writable bytes (K_SYSCALL_MEMORY_WRITE); deciding whether that size is sufficient for the requested channels and extra_samplings is delegated entirely to the driver. On a build with CONFIG_USERSPACE=y, a user-mode thread that has been granted the ADC device object could therefore submit a deliberately half-sized buffer and cause the driver's work-queue handler — which runs in supervisor mode, outside the caller's MPU restrictions — to write ADC conversion results past the end of that buffer, at an address and for a length of the caller's choosing. The overrun is bounded by the requested sequence: with sequence->options->extra_samplings set, the sampling loop walks the buffer pointer forward across every sampling, so the total overrun can reach the full size of the supplied buffer (kilobytes for a large extra_samplings). The written words are 16-bit ADC conversion results, so the content is only partially attacker-influenced (via the selected analog input, gain and resolution), but the destination and length are fully controlled — sufficient for kernel memory corruption, a crash, or a userspace-to-kernel privilege escalation. Builds without CONFIG_USERSPACE, or on SoCs other than NXP RW61x with the GAU ADC node enabled, are not exposed to the privilege boundary; there the same defect only causes a silent overflow when the application itself passes an undersized buffer. The fix replaces the ad-hoc check with the shared adc_sequence_validate_buffer() helper (validating against num_channels * sizeof(uint16_t)), stores buffer_size / sizeof(uint16_t) in results_length, and corrects the loop bound to a post-decrement so exactly the available number of slots may be written.
View the official NVD record for CVE-2026-19184
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-100103 |
Product identification pending PATCH
Reporter: SECURITY
|
10
CRITICAL
|
VIEW RECORD |
| CVE-2026-100102 |
Product identification pending PATCH
Reporter: SECURITY
|
9.5
CRITICAL
|
VIEW RECORD |
| CVE-2026-103510 |
Product identification pending PATCH
Reporter: SECURITY
|
9.5
CRITICAL
|
VIEW RECORD |
| CVE-2026-105207 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105209 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105215 |
zitadel PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105086 |
AVideo
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105089 |
AVideo
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105284 |
A3002MU
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105285 |
A3002MU
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105211 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-105293 |
Legcord
Reporter: DISCLOSURE
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-105216 |
go-micro PATCH
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105218 |
gopay PATCH
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105221 |
gist PATCH
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105222 |
google-maps
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105223 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105294 |
Legcord
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105210 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-105213 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-20586 |
Product identification pending
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-105208 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-105212 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-105219 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-105220 |
Product identification pending
Reporter: DISCLOSURE
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-104389 |
Sirv PATCH
Reporter: AUDIT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-104805 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-20521 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-20522 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-20523 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-20524 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-20531 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-104706 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-104809 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-104810 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-104811 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-19184 |
Product identification pending
Reporter: VULNERABILITIES
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-19185 |
Product identification pending
Reporter: VULNERABILITIES
|
7.8
HIGH
|
VIEW RECORD |
| CVE-2026-105295 |
Product identification pending
Reporter: DISCLOSURE
|
7.7
HIGH
|
VIEW RECORD |
| CVE-2026-104408 |
Groundhogg PATCH
Reporter: AUDIT
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-20519 |
Product identification pending
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-20520 |
Product identification pending
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-20526 |
Product identification pending
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-105314 |
Product identification pending
Reporter: CVE
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103507 |
Product identification pending PATCH
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-104407 |
PowerPress Podcasting PATCH
Reporter: AUDIT
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105205 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105161 |
aiir
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105163 |
crossplane-runtime PATCH
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-100727 |
GROWI
Reporter: VULTURES
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-59782 |
Product identification pending
Reporter: SECURITY
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-59786 |
Product identification pending
Reporter: SECURITY
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-20544 |
Product identification pending
Reporter: SECURITY
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-20528 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20529 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20530 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20533 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20535 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20536 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20537 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20542 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20579 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20587 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20588 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20589 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-19395 |
Qt for MCUs
Reporter: A59D8014-47C4-4630-AB43-E1B13CBE58E3
|
6.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-105306 |
Product identification pending
Reporter: SECALERT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-102393 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-102914 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-103084 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104386 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104396 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104400 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104404 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104409 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104673 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105056 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105060 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105064 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105069 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-20532 |
Product identification pending
Reporter: SECURITY
|
6.2
MEDIUM
|
VIEW RECORD |
| CVE-2026-105292 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6
MEDIUM
|
VIEW RECORD |
| CVE-2026-13607 |
File Uploads Addon for WooCommerce
Reporter: CONTACT
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-78371 |
File Uploads Addon for WooCommerce PATCH
Reporter: CONTACT
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105302 |
Product identification pending
Reporter: SECALERT
|
5.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-59788 |
Product identification pending
Reporter: SECURITY
|
5.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-105147 |
R2R
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105148 |
R2R
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105149 |
mooSocial
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105158 |
DocSys
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105166 |
food-waste-management-system
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105167 |
food-waste-management-system
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105169 |
food-waste-management-system
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105170 |
food-waste-management-system
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105172 |
Online Admission System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105175 |
Drug Recommendation System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-20543 |
Product identification pending
Reporter: SECURITY
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105182 |
Online Reviewer Management System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105183 |
Online Admission System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105184 |
Online Admission System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.