Over-the-Air Update Client Vulnerability in Zephyr Project by Nordic Semiconductor
CVE-2026-11811

3.7LOW

Key Information:

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-11811?

The UpdateHub over-the-air update client within the Zephyr Project has a vulnerability that leads to socket descriptor leaks during connection setup failures. When the client is unable to establish a connection, the cleanup of the socket is not executed properly, causing the descriptor to remain open. This results in a gradual decline in networking capabilities until the device is rebooted, creating a denial-of-service condition. The issue is exacerbated by network disruptions or server unreachability, which can prompt frequent connection attempts. Although the severity is noted as low due to the limited leak rate dictated by a default polling interval, affected builds can experience device-wide network degradation. There is no risk of memory corruption, information disclosure, or authentication issues.

Affected Version(s)

zephyr 2.0.0 < 4.4.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.