A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3.

Project Subscriptions

Vendors Products
Elan Microelectronics Corp. Subscribe
Elan Smart-pad Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update to ETD driver version to ETD24.21.53.3 or later.


Workaround

No workaround given by the vendor.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Elan Microelectronics Corp.
Elan Microelectronics Corp. elan Smart-pad
Vendors & Products Elan Microelectronics Corp.
Elan Microelectronics Corp. elan Smart-pad

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Stack‑based Buffer Overflow in ELAN Smart‑Pad Driver Causes BSOD

Thu, 06 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded to ETD.sys where it is used as a loop counter for a stack buffer copy without destination size validation. A local attacker with standard user privileges can trigger a kernel bugcheck (BSOD 0xF7 DRIVER_OVERRAN_STACK_BUFFER), resulting in denial of service. This issue affects ELAN Smart-Pad through ETD24.21.52.3.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:P/AU:N/R:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ELAN

Published:

Updated: 2026-08-06T14:19:21.022Z

Reserved: 2026-08-05T05:41:07.711Z

Link: CVE-2026-18909

cve-icon Vulnrichment

Updated: 2026-08-06T14:19:17.961Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:04:48Z

Weaknesses