PT-2026-90984 · Mcumgr · Mcumgr

CVE-2026-15892

·

Published

2026-09-13

·

Updated

2026-09-14

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions mcumgr (affected versions not specified)
Description A memory leak occurs in the SMP settings-management group handlers settings mgmt read(), settings mgmt write(), and settings mgmt delete() within subsys/mgmt/mcumgr/grp/settings mgmt/src/settings mgmt.c. When CONFIG MCUMGR GRP SETTINGS BUFFER TYPE HEAP and CONFIG MCUMGR GRP SETTINGS ACCESS HOOK are both enabled, the handlers allocate a key name buffer (and a data buffer for read operations) using k malloc(). If the application access hook rejects a request by returning the status MGMT CB ERROR RC, the handler returns immediately, bypassing the k free() call and leaking the allocated memory.
These handlers are accessible via unauthenticated SMP transport, such as Bluetooth LE, UART, or UDP. An attacker can trigger this leak by sending read, write, or delete commands that are rejected by the access hook. Since the leaked memory is not reclaimed until a reboot, a continuous stream of rejected requests can exhaust the kernel heap, leading to a denial of service that affects the mcumgr service and other heap consumers on the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary mitigation, disable the CONFIG MCUMGR GRP SETTINGS BUFFER TYPE HEAP configuration to use the default stack buffer type, which is not susceptible to this leak.

Exploit

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15892
GHSA-RQ68-WGV4-HCQ3

Affected Products

Mcumgr