PT-2026-102412 · Zephyr · Zephyr Lwm2M Client
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Zephyr LwM2M client (affected versions not specified)
Description
The
parse write op() function in subsys/net/lib/lwm2m/lwm2m message handling.c contains a NULL pointer dereference when handling inbound CoAP WRITE/CREATE requests with a Block1 option. The issue occurs during the first block of a transfer when init block ctx() is called; the system stores the peer-selected block size in block ctx->ctx.block size before verifying the return code. If the static block1 contexts[] pool is exhausted (default 3 entries), init block ctx() returns -ENOMEM and sets the pointer to NULL, leading to a crash.An attacker or a legitimate server can trigger this by initiating four concurrent block-wise writes on distinct object paths. In NoSec deployments, this is reachable via the connected UDP socket without credentials. The resulting memory fault typically causes the device to crash or reset, though confidentiality and integrity remain unaffected.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zephyr Lwm2M Client