CVE-2026-18909 Details
Description
A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3.
A stack-based buffer overflow vulnerability has been identified in ELAN Microelectronics Corp. ELAN Smart-Pad devices running Windows, specifically within the drivers ETD.sys and ETDSMBus.sys. The vulnerability arises during Intel SMBus recovery, where ETDSMBus.sys fails to properly validate the upper limit of the hardware-derived report count. This oversight allows an out-of-range value to be passed to ETD.sys, where it is improperly used as a loop counter for copying data into a stack buffer without checking the destination size. A local attacker with standard user privileges can exploit this vulnerability, causing a kernel bugcheck that leads to a Blue Screen of Death (BSOD) with the error code 0xF7 DRIVER_OVERRAN_STACK_BUFFER, thereby creating a denial-of-service condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.emc.com.tw/emc/tw/vulnerability-disclosure-policy | ELAN Microelectronics |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | ELAN Microelectronics |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | ELAN Microelectronics |