PT-2026-96155 · Zephyr · Zephyr

CVE-2026-17050

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

5.7

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Zephyr versions 4.1.0 through 4.4.x
Description The experimental USB host stack contains a double free issue in the usb device heap. In the usbh device set configuration() function within subsys/usb/host/usbh device.c, a configuration-descriptor buffer udev->cfg desc is allocated. If a failure occurs during a full-length GET DESCRIPTOR(CONFIGURATION) read, a mismatch between short and full descriptor reads, or a rejected descriptor in parse configuration descriptor(), the buffer is released using k heap free(), but the pointer remains dangling. Subsequent cleanup in usbh device free() triggers a second free of the same memory block.
A malicious or malformed USB peripheral can trigger this by providing a well-formed header in the initial 9-byte configuration-descriptor request and then failing subsequent checks. Depending on the build configuration, this leads to either a deterministic denial of service via k panic() when CONFIG SYS HEAP HARDENING BASIC is active, or heap corruption when CONFIG SYS HEAP HARDENING NONE is used, potentially allowing later allocations to return overlapping or invalid blocks.
Recommendations Update Zephyr to a version where udev->cfg desc is set to NULL after every k heap free() call. As a temporary mitigation, disable the experimental USB host stack by ensuring CONFIG USB HOST STACK is disabled.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17050
GHSA-R7XW-9JHG-88CM

Affected Products

Zephyr