CVE-2026-12365: use-after-free in zephyrproject zephyr
CVE-2026-12365 is a use-after-free vulnerability in the Zephyr project's kernel work queue implementation affecting delayable work timeouts. It occurs when a delayable work item's timeout handler is concurrently canceled without proper synchronization, leading to kernel memory corruption or crash. The flaw requires an SMP build and specific timing conditions involving subsystem timers. The vulnerability impacts kernel stability but does not allow privilege escalation from userspace.
AI Analysis
Technical Summary
This vulnerability exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work item's timeout handler is in progress and a concurrent cancellation occurs, the cancellation does not wait for the handler to complete. This can lead to a use-after-free condition where the handler dereferences freed memory, causing kernel memory corruption or crash. The issue requires SMP builds and specific timing to trigger. The fix involves making the cancellation wait for the handler to finish and switching to atomic ownership of the delayed work bit, preventing the race conditions.
Potential Impact
The vulnerability can cause kernel memory corruption or a denial of service (kernel crash). It does not provide a path for userspace privilege escalation since the affected API is kernel-mode only. Exploitation requires specific timing and concurrency conditions in SMP builds, making it a probabilistic attack vector rather than a straightforward exploit.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The described fix involves changes to the kernel work queue code to wait for in-flight handlers before cancellation completes and to use atomic ownership flags. Until an official fix is released, users should avoid scenarios that trigger concurrent cancellation and freeing of delayable work items in SMP environments.
CVE-2026-12365: use-after-free in zephyrproject zephyr
Description
CVE-2026-12365 is a use-after-free vulnerability in the Zephyr project's kernel work queue implementation affecting delayable work timeouts. It occurs when a delayable work item's timeout handler is concurrently canceled without proper synchronization, leading to kernel memory corruption or crash. The flaw requires an SMP build and specific timing conditions involving subsystem timers. The vulnerability impacts kernel stability but does not allow privilege escalation from userspace.
CVSS v3.1
Score 5.8medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work item's timeout handler is in progress and a concurrent cancellation occurs, the cancellation does not wait for the handler to complete. This can lead to a use-after-free condition where the handler dereferences freed memory, causing kernel memory corruption or crash. The issue requires SMP builds and specific timing to trigger. The fix involves making the cancellation wait for the handler to finish and switching to atomic ownership of the delayed work bit, preventing the race conditions.
Potential Impact
The vulnerability can cause kernel memory corruption or a denial of service (kernel crash). It does not provide a path for userspace privilege escalation since the affected API is kernel-mode only. Exploitation requires specific timing and concurrency conditions in SMP builds, making it a probabilistic attack vector rather than a straightforward exploit.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The described fix involves changes to the kernel work queue code to wait for in-flight handlers before cancellation completes and to use atomic ownership flags. Until an official fix is released, users should avoid scenarios that trigger concurrent cancellation and freeing of delayable work items in SMP environments.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- zephyr
- Date Reserved
- 2026-06-16T03:53:45.082Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7f5a78bf8831d539821041
Added to database: 08/14/2026, 18:12:08 UTC
Last enriched: 08/14/2026, 18:29:19 UTC
Last updated: 08/14/2026, 18:29:19 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.