The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data pointer and data_len, and neither was passed through K_SYSCALL_MEMORY() before the payload was handed to z_impl_i3c_do_ccc() and on to the controller driver. The verifier also operated on the caller's live structure rather than a snapshot, so validated fields could be changed by a second user thread between the check and the driver's use — unlike the sibling z_vrfy_i3c_transfer(), which has always copied its message array first. The defect is only present in CONFIG_USERSPACE builds, where drivers/i3c/i3c_handlers.c is compiled. An unprivileged user-mode thread that has been granted access to the I3C controller device object — the ordinary way an application lets a user threa
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-19185 is a privilege escalation vulnerability in the Zephyr RTOS i3c_do_ccc() system call handler that fails to validate memory buffers referenced by per-target payload structures. While the verifier checks the outer i3c_ccc_payload struct and some nested buffers, it bypasses validation of the data pointers and lengths within individual i3c_ccc_target_payload array elements before passing them to kernel implementation code. This creates a classic use-after-free and memory access vulnerability that allows unprivileged user-space processes to read or write arbitrary kernel memory, potentially leading to privilege escalation or denial of service. The vulnerability affects embedded and IoT systems running Zephyr RTOS with I3C device drivers, where the I3C controller interface is accessible to untrusted applications.
Casky's 754 security skills mapped to MITRE ATT&CK enable detection of the exploitation patterns underlying this vulnerability, even though no specific ATT&CK techniques are currently mapped to this CVE. Practitioners using Casky would identify red flags associated with T1548 (Abuse Elevation Control Mechanism) through Claude AI's extended reasoning detecting suspicious i3c_do_ccc() calls with pointer arithmetic or buffer overwrites. Additionally, skills correlating to T1562 (Impair Defenses) would surface incomplete system call validation patterns, while T1083 (File and Directory Discovery) patterns could reveal attempts to probe kernel memory structures through malformed I3C payloads. Security teams would see findings highlighting the gap between validated and unvalidated buffer chains in system call handlers—a pattern Casky's skills recognize as high-risk privilege boundary violations in embedded kernel code.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-19185. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation