PT-2026-102412 · Zephyr · Zephyr Lwm2M Client

·

CVE-2026-18746

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zephyr LwM2M client (affected versions not specified)
Description The parse write op() function in subsys/net/lib/lwm2m/lwm2m message handling.c contains a NULL pointer dereference when handling inbound CoAP WRITE/CREATE requests with a Block1 option. The issue occurs during the first block of a transfer when init block ctx() is called; the system stores the peer-selected block size in block ctx->ctx.block size before verifying the return code. If the static block1 contexts[] pool is exhausted (default 3 entries), init block ctx() returns -ENOMEM and sets the pointer to NULL, leading to a crash.
An attacker or a legitimate server can trigger this by initiating four concurrent block-wise writes on distinct object paths. In NoSec deployments, this is reachable via the connected UDP socket without credentials. The resulting memory fault typically causes the device to crash or reset, though confidentiality and integrity remain unaffected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18746
GHSA-4Q9G-2MHH-M7W7

Affected Products

Zephyr Lwm2M Client