CVE-2026-18417
Received Received - Intake

Type Confusion in Zephyr RTOS BSD Socket Layer

Vulnerability report for CVE-2026-18417, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Zephyr Project

Description

The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_connected_cb() and zsock_close_ctx() in subsys/net/lib/sockets/sockets_inet.c), reading it back with POINTER_TO_INT(). That same field is owned by the network stack for listening TCP contexts: net_tcp_accept() stores the parent context pointer there and the TCP core passes it back to the registered accept callback. A failed accept therefore left a small integer (an errno value) where the stack expected a struct net_context . When the network interface carrying a listening TCP socket goes down, close_tcp_conn() in subsys/net/ip/tcp.c invokes the accept callback with -ENETDOWN and the context's user_data. In v4.3.0 the callback was not disarmed afterwards, so a second interface-down event forwarded the previously stored errno to zsock_accepted_cb(), which dereferenced it as the parent context and performed several stores through it (sock_set_error()'s read-modify-write of socket_data, k_fifo_cancel_wait(&parent->recv_q)) β€” the crash described in the fix's commit message. v4.3.1 and v4.4.x carry a later change clearing conn->accept_cb after the error callback (269cb8823d3 on the v4.3 branch, 913fae5169425550f2364655298fceb79b320066 on main), which closes that repeat path; on those releases the poisoned cookie remains reachable only by a narrower race, a handshake completing alongside the interface-down still passing the stale cookie to k_fifo_put(&parent->accept_q, ...), and by getsockopt(SO_ERROR), which reads the field back unconditionally. On v4.3.0 an application that keeps a listening TCP socket open across repeated link-down events is sufficient to reach the defect; the triggering condition is a network-interface state change, not attacker-supplied packet data, so the practical attacker is one able to force the link down repeatedly (for example an adjacent attacker disrupting a wireless link) or one with local/physical access. Because both the faulting address and the stored data are fixed small constants derived from the errno value, the outcome is a wild-pointer access leading to a kernel fatal error β€” a denial of service (device crash or reset) rather than an attacker-directed memory corruption. The fix stores the pending error in a dedicated net_context.sock_error field and converts every producer and consumer to sock_set_error()/sock_get_error(), leaving user_data untouched. As a side effect it also stops getsockopt(SO_ERROR) β€” which is evaluated unconditionally β€” from returning the kernel address held in user_data to a userspace application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
zephyrproject zephyr to 4.4.2 (exc)
zephyrproject zephyr 4.3.1
zephyrproject zephyr 4.4.0
zephyrproject zephyr 4.4.1
zephyrproject zephyr 4.4.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a wild pointer dereference in Zephyr RTOS's BSD sockets layer. When a TCP listening socket encounters an asynchronous error, the system incorrectly stores the error (an errno value) in the user_data field of a net_context structure. This field is normally used by the network stack to hold a pointer to the parent context. When the network interface goes down, the error is forwarded to the accept callback, which then tries to use the error value as a valid context pointer, causing a kernel crash due to invalid memory access.

Detection Guidance

Detecting this vulnerability requires checking Zephyr RTOS versions and monitoring for kernel crashes during network interface state changes. Commands include: 1) Check Zephyr version with grep -r 'CONFIG_VERSION' in your build directory. 2) Monitor system logs for kernel panics or fatal errors during interface down events. 3) Use netstat -tuln to verify listening TCP sockets remain stable after interface transitions.

Impact Analysis

The vulnerability can lead to a denial-of-service condition where the device crashes or resets. An attacker needs the ability to repeatedly force a network interface down, such as via physical access or disrupting a wireless link. This causes a kernel fatal error due to wild pointer access, but does not allow arbitrary memory corruption.

Compliance Impact

This vulnerability primarily causes a denial-of-service condition by crashing the device or resetting it, which could lead to unavailability of critical services. For compliance with standards like GDPR or HIPAA, availability is a key requirement; prolonged downtime may violate availability obligations under these regulations. The crash risk could also impact integrity if data processing is interrupted unexpectedly.

Mitigation Strategies

Upgrade Zephyr RTOS to version 4.4.2 or later where the fix is included. If upgrading is not immediately possible, avoid keeping listening TCP sockets open across repeated network interface state changes. Implement network redundancy to reduce interface down events. Apply the official patch from the Zephyr GitHub repository if custom builds are used.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18417. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart