Network Stack Vulnerability in Zephyr OS by Nordic Semiconductor
CVE-2026-18417

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-18417?

This vulnerability involves the improper handling of asynchronous socket errors in the BSD-socket layer of Zephyr OS, leading to potential Denial of Service (DoS). When the network interface experiences a state change, it can trigger a crash if a listening TCP socket remains open. This issue arises because error information, which should be stored separately, is erroneously written to a field expected to point to a network context. Attackers can exploit this by causing repeated link-down events, resulting in wild-pointer access and, consequently, a kernel fatal error. The fix implemented in later versions addresses this concern by refining how errors are managed, ensuring that the socket's user data remains intact while correctly managing error states.

Affected Version(s)

zephyr 4.3.0 < 4.4.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.