TCP ISN Implementation Vulnerability in Zephyr RTOS by Zephyr Project
CVE-2026-19735

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-19735?

The implementation of TCP Initial Sequence Numbers (ISN) in Zephyr RTOS can be compromised due to a failure in the cryptographic random source. If sys_csrand_get() fails during initialization, it may leave the unique key in a zero state, allowing an off-path attacker to predict ISNs. This exposes devices to potential TCP connection spoofing and blind data injections since the random value becomes predictable based on the connection four-tuple and the device's time offset. The identified issue has been addressed by restructuring key generation logic to ensure proper error handling and fallback mechanisms.

Affected Version(s)

zephyr 3.7.0 <= 4.4.2

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.