PT-2026-102411 · Zephyr · Zephyr
CVE-2026-18417
·
Published
2026-09-28
·
Updated
2026-09-29
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Zephyr versions 4.3.0 through 4.4.x
Description
The native BSD-socket layer incorrectly records pending asynchronous socket errors by storing them in the
user data field of the net context structure. This field is also used by the network stack for listening TCP contexts to store parent context pointers. When a failed accept occurs, an error value is stored where a pointer is expected. In version 4.3.0, repeated network interface-down events can trigger the zsock accepted cb() function to dereference this error value as a pointer, leading to a wild-pointer access and a kernel fatal error, resulting in a denial of service. In versions 4.3.1 and 4.4.x, the issue persists through a narrower race condition during handshakes or via the getsockopt(SO ERROR) function. The flaw is triggered by network-interface state changes rather than attacker-supplied packets.Technical details include the following vulnerable functions:
zsock accepted cb()zsock received cb()zsock connected cb()zsock close ctx()net tcp accept()close tcp conn()
Recommendations
Update Zephyr to a version where pending errors are stored in a dedicated
net context.sock error field and the user data field remains untouched.
As a temporary mitigation, restrict the ability of unauthorized users to force network link-down events or limit local/physical access to the device.Exploit
Fix
DoS
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zephyr