CVE-2026-17053 | ZephyrProject Zephyr up to 4.4.1 SMBus Driver API smbus_handlers.c cb input validation

SecurityVulns

A vulnerability marked as very critical has been reported in ZephyrProject Zephyr up to 4.4.1. Impacted is the function smbus_smbalert_remove_cb/smbus_host_notify_remove_cb of the file drivers/smbus/smbus_handlers.c of the component SMBus Driver API. The manipulation of the argument cb leads to improper input validation.

This vulnerability is listed as CVE-2026-17053. The attack must be carried out locally. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More