Skip to main content
Disclosures

Zephyr Project · Zephyr

ATAES132A Response Length Allows Stack Buffer Overflow

3.8low
SecMateSECMATE-2025-0029
VendorZephyr Project
ProductZephyr
VectorCVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Timeline
Published
Mar 14, 2026
Summary

A stack buffer overflow vulnerability exists in Zephyr's ATAES132A crypto driver. A malformed device response with an oversized length field can overflow a 52-byte stack buffer in ataes132a_send_command. An attacker controlling the device or I2C bus could trigger this vulnerability to corrupt kernel memory.

What's hidden in yours?

Find out