PT-2026-96272 · Zephyr · Zephyr
CVE-2026-15890
·
Published
2026-09-21
·
Updated
2026-09-29
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Zephyr (affected versions not specified)
Description
An issue exists in the PSA Internal Trusted Storage (ITS) transform module where the function
secure storage its transform aead get nonce() uses unsynchronized function-local static variables s nonce and s nonce initialized to store its nonce counter. Due to the lack of locking mechanisms, concurrent calls from multiple threads can lead to a race condition during the initialization path (using psa generate random() and memcpy()) or the increment-then-copy path. This can result in the same nonce being assigned to two distinct encryption operations or the loss of increments, causing the counter to repeat values.Since the ITS layer function
secure storage its set() does not perform serialization, concurrent writes to the same User Identifier (UID) can trigger this failure. Reusing a nonce with the same key in AES-GCM or ChaCha20-Poly1305 (Authenticated Encryption with Associated Data - AEAD) can leak the XOR of two plaintexts and, in the case of GCM, expose the authentication key, allowing for the forgery of stored entries. This is particularly exploitable in log-structured flash stores like zms.c and the settings/NVS back-end in settings.c, where superseded entries remain physically present until garbage collection occurs.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zephyr