What is CVE-2026-18909?
A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad drivers (ETD.sys and ETDSMBus.sys) on Windows. During Intel SMBus recovery, ETDSMBus.sys fails to validate the hardware-derived report count, allowing an out-of-range value to be used. Applying the vendor's updates is recommended.
Azərbaycanca: ELAN Microelectronics şirkətinin Windows üçün ELAN Smart-Pad sürücülərində (ETD.sys və ETDSMBus.sys) stack-based buffer overflow zəifliyi aşkarlanıb. Bu, Intel SMBus recovery zamanı ETDSMBus.sys-in hardware-dan gələn report count dəyərini yoxlamaması səbəbindən yaranır. İstehsalçı tərəfindən buraxılmış yeniləmələrin tətbiq edilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Intel
FAQ2
What mechanism causes the CVE-2026-18909 vulnerability in the ELAN Smart-Pad drivers?
The vulnerability occurs because the ETDSMBus.sys driver fails to validate the hardware-derived report count during Intel SMBus recovery.
What security measure is recommended for CVE-2026-18909?
Applying the vendor's updates is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.