CVE-2026-19185: Product identification pending
- Severity
- 7.8 (HIGH)
- Vendor
- ZEPHYRPROJECT
- Patch status
- Unknown
- Published
- 2026-10-05T09:17:13.077
- Modified
- 2026-10-05T09:17:13.077
Why it matters
High-severity vulnerability requiring prioritized review.
Recommended admin actions
- Review and patch based on exposure, asset criticality, and business impact.
- Compare installed versions against the affected version range in the advisory.
Technical summary
The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data pointer and data_len, and neither was passed through K_SYSCALL_MEMORY() before the payload was handed to z_impl_i3c_do_ccc() and on to the controller driver. The verifier also operated on the caller's live structure rather than a snapshot, so validated fields could be changed by a second user thread between the check and the driver's use — unlike the sibling z_vrfy_i3c_transfer(), which has always copied its message array first. The defect is only present in CONFIG_USERSPACE builds, where drivers/i3c/i3c_handlers.c is compiled. An unprivileged user-mode thread that has been granted access to the I3C controller device object — the ordinary way an application lets a user thread talk to I3C peripherals — can issue a direct CCC whose target payload data pointer names an arbitrary kernel address. Controller drivers dereference that pointer directly (for example drivers/i3c/i3c_mcux.c, drivers/i3c/i3c_cdns.c, drivers/i3c/i3c_stm32.c, drivers/i3c/i3c_npcx.c), using rnw to decide direction. A read CCC therefore causes the kernel-mode driver to write bus-received bytes into an attacker-chosen kernel address for an attacker-chosen length, and a write CCC transmits kernel memory out onto the I3C bus. The result is an out-of-bounds kernel write plus a kernel memory disclosure, i.e. escalation from a user-mode thread to supervisor privilege, defeating the isolation CONFIG_USERSPACE is meant to provide. The fix introduces copy_ccc_and_do(), which snapshots the payload, copies the target array into kernel memory with k_usermode_alloc_from_copy() (bounding num_targets to fewer than 32), validates each per-target buffer with K_SYSCALL_MEMORY() according to rnw, and copies the driver-written num_xfer and err fields back to the caller.
View the official NVD record for CVE-2026-19185
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-100103 |
Product identification pending PATCH
Reporter: SECURITY
|
10
CRITICAL
|
VIEW RECORD |
| CVE-2026-100102 |
Product identification pending PATCH
Reporter: SECURITY
|
9.5
CRITICAL
|
VIEW RECORD |
| CVE-2026-103510 |
Product identification pending PATCH
Reporter: SECURITY
|
9.5
CRITICAL
|
VIEW RECORD |
| CVE-2026-105207 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105209 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105215 |
zitadel PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105086 |
AVideo
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105089 |
AVideo
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105284 |
A3002MU
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105285 |
A3002MU
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-105211 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-105293 |
Legcord
Reporter: DISCLOSURE
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-105216 |
go-micro PATCH
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105218 |
gopay PATCH
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105221 |
gist PATCH
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105222 |
google-maps
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105223 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105294 |
Legcord
Reporter: DISCLOSURE
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-105210 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-105213 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-20586 |
Product identification pending
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-105208 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-105212 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-105219 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-105220 |
Product identification pending
Reporter: DISCLOSURE
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-104389 |
Sirv PATCH
Reporter: AUDIT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-104805 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-20521 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-20522 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-20523 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-20524 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-20531 |
Product identification pending
Reporter: SECURITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-104706 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-104809 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-104810 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-104811 |
Mitel MiVoice Office 400
Reporter: VULNERABILITY
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-19184 |
Product identification pending
Reporter: VULNERABILITIES
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-19185 |
Product identification pending
Reporter: VULNERABILITIES
|
7.8
HIGH
|
VIEW RECORD |
| CVE-2026-105295 |
Product identification pending
Reporter: DISCLOSURE
|
7.7
HIGH
|
VIEW RECORD |
| CVE-2026-104408 |
Groundhogg PATCH
Reporter: AUDIT
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-20519 |
Product identification pending
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-20520 |
Product identification pending
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-20526 |
Product identification pending
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-105314 |
Product identification pending
Reporter: CVE
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103507 |
Product identification pending PATCH
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-104407 |
PowerPress Podcasting PATCH
Reporter: AUDIT
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105205 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105161 |
aiir
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105163 |
crossplane-runtime PATCH
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-100727 |
GROWI
Reporter: VULTURES
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-59782 |
Product identification pending
Reporter: SECURITY
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-59786 |
Product identification pending
Reporter: SECURITY
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-20544 |
Product identification pending
Reporter: SECURITY
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-20528 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20529 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20530 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20533 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20535 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20536 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20537 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20542 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20579 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20587 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20588 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-20589 |
Product identification pending
Reporter: SECURITY
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-19395 |
Qt for MCUs
Reporter: A59D8014-47C4-4630-AB43-E1B13CBE58E3
|
6.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-105306 |
Product identification pending
Reporter: SECALERT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-102393 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-102914 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-103084 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104386 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104396 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104400 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104404 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104409 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-104673 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105056 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105060 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105064 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105069 |
Product identification pending
Reporter: AUDIT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-20532 |
Product identification pending
Reporter: SECURITY
|
6.2
MEDIUM
|
VIEW RECORD |
| CVE-2026-105292 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6
MEDIUM
|
VIEW RECORD |
| CVE-2026-13607 |
File Uploads Addon for WooCommerce
Reporter: CONTACT
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-78371 |
File Uploads Addon for WooCommerce PATCH
Reporter: CONTACT
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105302 |
Product identification pending
Reporter: SECALERT
|
5.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-59788 |
Product identification pending
Reporter: SECURITY
|
5.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-105147 |
R2R
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105148 |
R2R
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105149 |
mooSocial
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105158 |
DocSys
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105166 |
food-waste-management-system
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105167 |
food-waste-management-system
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105169 |
food-waste-management-system
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105170 |
food-waste-management-system
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105172 |
Online Admission System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105175 |
Drug Recommendation System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-20543 |
Product identification pending
Reporter: SECURITY
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105182 |
Online Reviewer Management System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105183 |
Online Admission System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-105184 |
Online Admission System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.