PT-2026-96272 · Zephyr · Zephyr

CVE-2026-15890

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v3.1

5.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zephyr (affected versions not specified)
Description An issue exists in the PSA Internal Trusted Storage (ITS) transform module where the function secure storage its transform aead get nonce() uses unsynchronized function-local static variables s nonce and s nonce initialized to store its nonce counter. Due to the lack of locking mechanisms, concurrent calls from multiple threads can lead to a race condition during the initialization path (using psa generate random() and memcpy()) or the increment-then-copy path. This can result in the same nonce being assigned to two distinct encryption operations or the loss of increments, causing the counter to repeat values.
Since the ITS layer function secure storage its set() does not perform serialization, concurrent writes to the same User Identifier (UID) can trigger this failure. Reusing a nonce with the same key in AES-GCM or ChaCha20-Poly1305 (Authenticated Encryption with Associated Data - AEAD) can leak the XOR of two plaintexts and, in the case of GCM, expose the authentication key, allowing for the forgery of stored entries. This is particularly exploitable in log-structured flash stores like zms.c and the settings/NVS back-end in settings.c, where superseded entries remain physically present until garbage collection occurs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15890
GHSA-23JW-7XV2-XR28

Affected Products

Zephyr