CVE-2026-18746: memory-safety in zephyrproject zephyr
CVE-2026-18746 is a memory-safety vulnerability in the Zephyr project's LwM2M message handling code. It occurs when processing inbound CoAP WRITE/CREATE requests with a Block1 option, leading to a NULL pointer dereference and a fatal memory fault that causes device crashes or resets. The flaw arises from improper handling of block context allocation and validation. This vulnerability does not affect confidentiality or integrity but results in denial of service. It affects Zephyr versions from 3.7.0 up to but not including 4.5.0. The CVSS score is 5.9 (medium severity).
AI Analysis
Technical Summary
The vulnerability exists in parse_write_op() within subsys/net/lib/lwm2m/lwm2m_message_handling.c of Zephyr. When handling the first block of a block-wise CoAP transfer, the function calls init_block_ctx(), which may return -ENOMEM and set the context pointer to NULL if no free block context is available. However, the code immediately stores a value into the context pointer without verifying it is non-NULL, causing a NULL pointer dereference. An attacker can exploit this by initiating multiple incomplete block-wise writes to exhaust the block context pool and then trigger the dereference with a fourth write. The impact is a fatal memory fault (BusFault or corrupted low memory), causing device crashes or resets. The vulnerability does not compromise confidentiality or integrity. The fix involves validating the context pointer before use and moving the store operation below the guard. The affected versions are Zephyr >=3.7.0 and <4.5.0.
Potential Impact
Successful exploitation leads to a denial of service via device crash or reset due to a fatal memory fault caused by NULL pointer dereference. Confidentiality and integrity are not impacted. The vulnerability can be triggered by an unauthenticated attacker in NoSec deployments or by legitimate servers running multiple concurrent block transfers.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The fix described involves validating the block context pointer before use to prevent NULL dereference. Until a patch is applied, limiting the number of concurrent block-wise transfers or enabling DTLS support (CONFIG_LWM2M_DTLS_SUPPORT) may reduce exposure, but no official mitigation is confirmed in the provided data.
CVE-2026-18746: memory-safety in zephyrproject zephyr
Description
CVE-2026-18746 is a memory-safety vulnerability in the Zephyr project's LwM2M message handling code. It occurs when processing inbound CoAP WRITE/CREATE requests with a Block1 option, leading to a NULL pointer dereference and a fatal memory fault that causes device crashes or resets. The flaw arises from improper handling of block context allocation and validation. This vulnerability does not affect confidentiality or integrity but results in denial of service. It affects Zephyr versions from 3.7.0 up to but not including 4.5.0. The CVSS score is 5.9 (medium severity).
CVSS v3.1
Score 5.9medium
Affected software
zephyrproject
zephyr
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in parse_write_op() within subsys/net/lib/lwm2m/lwm2m_message_handling.c of Zephyr. When handling the first block of a block-wise CoAP transfer, the function calls init_block_ctx(), which may return -ENOMEM and set the context pointer to NULL if no free block context is available. However, the code immediately stores a value into the context pointer without verifying it is non-NULL, causing a NULL pointer dereference. An attacker can exploit this by initiating multiple incomplete block-wise writes to exhaust the block context pool and then trigger the dereference with a fourth write. The impact is a fatal memory fault (BusFault or corrupted low memory), causing device crashes or resets. The vulnerability does not compromise confidentiality or integrity. The fix involves validating the context pointer before use and moving the store operation below the guard. The affected versions are Zephyr >=3.7.0 and <4.5.0.
Potential Impact
Successful exploitation leads to a denial of service via device crash or reset due to a fatal memory fault caused by NULL pointer dereference. Confidentiality and integrity are not impacted. The vulnerability can be triggered by an unauthenticated attacker in NoSec deployments or by legitimate servers running multiple concurrent block transfers.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The fix described involves validating the block context pointer before use to prevent NULL dereference. Until a patch is applied, limiting the number of concurrent block-wise transfers or enabling DTLS support (CONFIG_LWM2M_DTLS_SUPPORT) may reduce exposure, but no official mitigation is confirmed in the provided data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- zephyr
- Date Reserved
- 2026-08-03T21:22:11.665Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abb1b0bf7a7c541069f1975
Added to database: 09/29/2026, 01:57:31 UTC
Last enriched: 09/29/2026, 01:58:14 UTC
Last updated: 09/29/2026, 04:22:16 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.