PT-2026-96155 · Zephyr · Zephyr
CVE-2026-17050
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v3.1
5.7
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Zephyr versions 4.1.0 through 4.4.x
Description
The experimental USB host stack contains a double free issue in the
usb device heap. In the usbh device set configuration() function within subsys/usb/host/usbh device.c, a configuration-descriptor buffer udev->cfg desc is allocated. If a failure occurs during a full-length GET DESCRIPTOR(CONFIGURATION) read, a mismatch between short and full descriptor reads, or a rejected descriptor in parse configuration descriptor(), the buffer is released using k heap free(), but the pointer remains dangling. Subsequent cleanup in usbh device free() triggers a second free of the same memory block.A malicious or malformed USB peripheral can trigger this by providing a well-formed header in the initial 9-byte configuration-descriptor request and then failing subsequent checks. Depending on the build configuration, this leads to either a deterministic denial of service via
k panic() when CONFIG SYS HEAP HARDENING BASIC is active, or heap corruption when CONFIG SYS HEAP HARDENING NONE is used, potentially allowing later allocations to return overlapping or invalid blocks.Recommendations
Update Zephyr to a version where
udev->cfg desc is set to NULL after every k heap free() call.
As a temporary mitigation, disable the experimental USB host stack by ensuring CONFIG USB HOST STACK is disabled.Exploit
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zephyr