CVE-2026-18417: memory-safety in zephyrproject zephyr
CVE-2026-18417 is a memory-safety vulnerability in the Zephyr project's native BSD-socket layer affecting versions from 4.3.0 up to but not including 4.4.2. The issue arises from improper handling of asynchronous socket errors by storing error codes in a field expected to hold a pointer, leading to wild-pointer dereferences when the network interface goes down repeatedly. This results in a kernel fatal error causing denial of service (device crash or reset). The vulnerability does not allow attacker-controlled memory corruption but can be triggered by forcing repeated network interface down events, such as disrupting a wireless link or having local access. The flaw was fixed by separating error storage from the user_data field and updating all related code paths accordingly.
AI Analysis
Technical Summary
The vulnerability involves the native BSD-socket layer in Zephyr where asynchronous socket errors are type-punned into the void user_data field of struct net_context, which is also used by the network stack to store a pointer to the parent context for listening TCP sockets. When a network interface carrying a listening TCP socket goes down, the accept callback is invoked with an error code stored in user_data, which is then dereferenced as a pointer, causing wild-pointer access and a kernel fatal error. This flaw affects Zephyr versions >=4.3.0 and <4.4.2. The root cause is that the error code (an errno value) overwrites a pointer field, leading to invalid memory accesses on repeated interface-down events. The fix introduced a dedicated sock_error field for storing errors and updated all producers and consumers to use sock_set_error()/sock_get_error(), preventing user_data corruption and eliminating the crash path.
Potential Impact
The vulnerability leads to a denial of service condition by causing a kernel fatal error (device crash or reset) when a listening TCP socket remains open across repeated network interface down events. There is no direct confidentiality or integrity impact, and no attacker-controlled memory corruption is possible. The practical attacker is one capable of forcing repeated link-down events, such as an adjacent attacker disrupting wireless connectivity or an attacker with local or physical access to the device.
Mitigation Recommendations
A fix is available and included in Zephyr versions 4.4.2 and later. The fix separates error storage from the user_data field and updates all related code paths to use dedicated error handling functions. Users should upgrade to version 4.4.2 or later to remediate this issue. No additional mitigation is required once the fix is applied.
CVE-2026-18417: memory-safety in zephyrproject zephyr
Description
CVE-2026-18417 is a memory-safety vulnerability in the Zephyr project's native BSD-socket layer affecting versions from 4.3.0 up to but not including 4.4.2. The issue arises from improper handling of asynchronous socket errors by storing error codes in a field expected to hold a pointer, leading to wild-pointer dereferences when the network interface goes down repeatedly. This results in a kernel fatal error causing denial of service (device crash or reset). The vulnerability does not allow attacker-controlled memory corruption but can be triggered by forcing repeated network interface down events, such as disrupting a wireless link or having local access. The flaw was fixed by separating error storage from the user_data field and updating all related code paths accordingly.
CVSS v3.1
Score 6.5medium
Affected software
zephyrproject
zephyr
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves the native BSD-socket layer in Zephyr where asynchronous socket errors are type-punned into the void user_data field of struct net_context, which is also used by the network stack to store a pointer to the parent context for listening TCP sockets. When a network interface carrying a listening TCP socket goes down, the accept callback is invoked with an error code stored in user_data, which is then dereferenced as a pointer, causing wild-pointer access and a kernel fatal error. This flaw affects Zephyr versions >=4.3.0 and <4.4.2. The root cause is that the error code (an errno value) overwrites a pointer field, leading to invalid memory accesses on repeated interface-down events. The fix introduced a dedicated sock_error field for storing errors and updated all producers and consumers to use sock_set_error()/sock_get_error(), preventing user_data corruption and eliminating the crash path.
Potential Impact
The vulnerability leads to a denial of service condition by causing a kernel fatal error (device crash or reset) when a listening TCP socket remains open across repeated network interface down events. There is no direct confidentiality or integrity impact, and no attacker-controlled memory corruption is possible. The practical attacker is one capable of forcing repeated link-down events, such as an adjacent attacker disrupting wireless connectivity or an attacker with local or physical access to the device.
Mitigation Recommendations
A fix is available and included in Zephyr versions 4.4.2 and later. The fix separates error storage from the user_data field and updates all related code paths to use dedicated error handling functions. Users should upgrade to version 4.4.2 or later to remediate this issue. No additional mitigation is required once the fix is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- zephyr
- Date Reserved
- 2026-07-30T17:54:13.939Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abb1b0bf7a7c541069f1974
Added to database: 09/29/2026, 01:57:31 UTC
Last enriched: 09/29/2026, 01:58:08 UTC
Last updated: 09/29/2026, 03:33:09 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.