A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update to ETD driver version to ETD24.21.53.3 or later.
Workaround
No workaround given by the vendor.
References
History
Thu, 06 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stack‑based Buffer Overflow in ELAN Smart‑Pad Driver Causes BSOD |
Thu, 06 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3. | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ELAN
Published:
Updated: 2026-08-06T03:46:00.081Z
Reserved: 2026-08-05T05:41:07.711Z
Link: CVE-2026-18909
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-06T05:30:16Z
Weaknesses