Over-the-Air Update Client Vulnerability in Zephyr Project by Nordic Semiconductor
CVE-2026-11811
What is CVE-2026-11811?
The UpdateHub over-the-air update client within the Zephyr Project has a vulnerability that leads to socket descriptor leaks during connection setup failures. When the client is unable to establish a connection, the cleanup of the socket is not executed properly, causing the descriptor to remain open. This results in a gradual decline in networking capabilities until the device is rebooted, creating a denial-of-service condition. The issue is exacerbated by network disruptions or server unreachability, which can prompt frequent connection attempts. Although the severity is noted as low due to the limited leak rate dictated by a default polling interval, affected builds can experience device-wide network degradation. There is no risk of memory corruption, information disclosure, or authentication issues.
Affected Version(s)
zephyr 2.0.0 < 4.4.2
