CVE-2026-12999: dos in zephyrproject zephyr
Description
CVE-2026-12999 is a denial-of-service vulnerability in the Infineon Airoc Wi-Fi driver within the Zephyr project. The vulnerability causes a permanent memory leak of network buffers on transmit failures, eventually exhausting the buffer pool and causing loss of Wi-Fi connectivity until the device is rebooted. The issue arises from failure to release allocated buffers on synchronous send errors. The vulnerability affects Zephyr versions from 3.6.0 up to but not including 4.4.2. The impact is availability-only, with no confidentiality or integrity effects. Exploitation requires complex conditions and is not known to be exploited in the wild. A fix has been implemented to properly release buffers on failure.
CVSS v3.1
Score 5.3medium
Affected software
zephyrproject
zephyr
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() allocates a fixed pool buffer for each outbound packet. When the underlying WHD library's whd_network_send_ethernet_data() returns a synchronous failure, the pre-fix driver returns an error without releasing the allocated buffer, causing a permanent leak. The fixed buffer pool (default 20 buffers) is shared for transmit and receive. Once depleted, subsequent allocations fail, causing both transmit and receive paths to fail and resulting in permanent Wi-Fi loss until reboot. The leak occurs only on transmit error paths and can be influenced by Wi-Fi-adjacent attackers through deauthentication or disassociation attacks. The fix releases the buffer on failure, preventing the leak. Additionally, a redundant semaphore release was removed with no security impact.
Potential Impact
The vulnerability causes a permanent denial of service by leaking network buffers on transmit failures, exhausting the fixed buffer pool and disabling Wi-Fi connectivity until the device is rebooted. There is no impact on confidentiality or integrity. Exploitation requires complex conditions such as inducing synchronous send failures, for example by deauthenticating the device. Ordinary transient failures can also accumulate to cause the issue over time. No known exploits are reported in the wild.
Mitigation Recommendations
A fix is available that properly releases the allocated buffer on transmit failure, preventing the leak and subsequent denial of service. Users should upgrade to Zephyr version 4.4.2 or later where this issue is resolved. No additional mitigation is required as the vulnerability is patched in the fixed versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- zephyr
- Date Reserved
- 2026-06-23T13:18:10.190Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8a0c19acd9273b497eb2a2
Added to database: 08/22/2026, 20:52:41 UTC
Last enriched: 09/11/2026, 01:48:39 UTC
Last updated: 10/06/2026, 18:48:19 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.