TCP ISN Implementation Vulnerability in Zephyr RTOS by Zephyr Project
CVE-2026-19735
4.8MEDIUM
What is CVE-2026-19735?
The implementation of TCP Initial Sequence Numbers (ISN) in Zephyr RTOS can be compromised due to a failure in the cryptographic random source. If sys_csrand_get() fails during initialization, it may leave the unique key in a zero state, allowing an off-path attacker to predict ISNs. This exposes devices to potential TCP connection spoofing and blind data injections since the random value becomes predictable based on the connection four-tuple and the device's time offset. The identified issue has been addressed by restructuring key generation logic to ensure proper error handling and fallback mechanisms.
Affected Version(s)
zephyr 3.7.0 <= 4.4.2
