3.8low
SecMateSECMATE-2025-0029
VendorZephyr Project
ProductZephyr
VectorCVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
AdvisoryGHSA-ff4p-3ggg-prp6
Timeline
Published
Mar 14, 2026
Summary
A stack buffer overflow vulnerability exists in Zephyr's ATAES132A crypto driver. A malformed device response with an oversized length field can overflow a 52-byte stack buffer in ataes132a_send_command. An attacker controlling the device or I2C bus could trigger this vulnerability to corrupt kernel memory.