Skip to main content

CVE-2026-18417: memory-safety in zephyrproject zephyr

0
Medium
VulnerabilityCVE-2026-18417cvecve-2026-18417
Published: 09/28/2026 (09/28/2026, 23:25:23 UTC)
Source: CVE Database V5
Vendor/Project: zephyrproject
Product: zephyr

Description

CVE-2026-18417 is a memory-safety vulnerability in the Zephyr project's native BSD-socket layer affecting versions from 4.3.0 up to but not including 4.4.2. The issue arises from improper handling of asynchronous socket errors by storing error codes in a field expected to hold a pointer, leading to wild-pointer dereferences when the network interface goes down repeatedly. This results in a kernel fatal error causing denial of service (device crash or reset). The vulnerability does not allow attacker-controlled memory corruption but can be triggered by forcing repeated network interface down events, such as disrupting a wireless link or having local access. The flaw was fixed by separating error storage from the user_data field and updating all related code paths accordingly.

CVSS v3.1

Score 6.5medium

Attack Vector
Adjacent Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

zephyrproject

zephyr

Affected versions
>=4.3.0 <4.4.2
GitHub Actionsmore threats →cve
zephyr
pkg:github/zephyr
Affected versions
>=4.3.0 <4.4.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 01:58:08 UTC

Technical Analysis

The vulnerability involves the native BSD-socket layer in Zephyr where asynchronous socket errors are type-punned into the void user_data field of struct net_context, which is also used by the network stack to store a pointer to the parent context for listening TCP sockets. When a network interface carrying a listening TCP socket goes down, the accept callback is invoked with an error code stored in user_data, which is then dereferenced as a pointer, causing wild-pointer access and a kernel fatal error. This flaw affects Zephyr versions >=4.3.0 and <4.4.2. The root cause is that the error code (an errno value) overwrites a pointer field, leading to invalid memory accesses on repeated interface-down events. The fix introduced a dedicated sock_error field for storing errors and updated all producers and consumers to use sock_set_error()/sock_get_error(), preventing user_data corruption and eliminating the crash path.

Potential Impact

The vulnerability leads to a denial of service condition by causing a kernel fatal error (device crash or reset) when a listening TCP socket remains open across repeated network interface down events. There is no direct confidentiality or integrity impact, and no attacker-controlled memory corruption is possible. The practical attacker is one capable of forcing repeated link-down events, such as an adjacent attacker disrupting wireless connectivity or an attacker with local or physical access to the device.

Mitigation Recommendations

A fix is available and included in Zephyr versions 4.4.2 and later. The fix separates error storage from the user_data field and updates all related code paths to use dedicated error handling functions. Users should upgrade to version 4.4.2 or later to remediate this issue. No additional mitigation is required once the fix is applied.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
zephyr
Date Reserved
2026-07-30T17:54:13.939Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6abb1b0bf7a7c541069f1974

Added to database: 09/29/2026, 01:57:31 UTC

Last enriched: 09/29/2026, 01:58:08 UTC

Last updated: 09/29/2026, 03:33:09 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses