PT-2026-102411 · Zephyr · Zephyr

CVE-2026-18417

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zephyr versions 4.3.0 through 4.4.x
Description The native BSD-socket layer incorrectly records pending asynchronous socket errors by storing them in the user data field of the net context structure. This field is also used by the network stack for listening TCP contexts to store parent context pointers. When a failed accept occurs, an error value is stored where a pointer is expected. In version 4.3.0, repeated network interface-down events can trigger the zsock accepted cb() function to dereference this error value as a pointer, leading to a wild-pointer access and a kernel fatal error, resulting in a denial of service. In versions 4.3.1 and 4.4.x, the issue persists through a narrower race condition during handshakes or via the getsockopt(SO ERROR) function. The flaw is triggered by network-interface state changes rather than attacker-supplied packets.
Technical details include the following vulnerable functions:
  • zsock accepted cb()
  • zsock received cb()
  • zsock connected cb()
  • zsock close ctx()
  • net tcp accept()
  • close tcp conn()
Recommendations Update Zephyr to a version where pending errors are stored in a dedicated net context.sock error field and the user data field remains untouched. As a temporary mitigation, restrict the ability of unauthorized users to force network link-down events or limit local/physical access to the device.

Exploit

Fix

DoS

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18417
GHSA-P8R8-8MW8-3WF9

Affected Products

Zephyr