CVE-2026-18746
Received Received - Intake

NULL Pointer Dereference in Zephyr RTOS LwM2M Block1 Handling

Vulnerability report for CVE-2026-18746, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Zephyr Project

Description

parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block size with block_ctx->ctx.block_size = block_size before inspecting the return code. init_block_ctx() sets the caller's pointer to NULL and returns -ENOMEM when no entry of the static block1_contexts[] pool is free or timed out, so that store dereferences a NULL pointer. The pool holds CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries (default 3) and an entry is only reclaimed once its transfer completes, fails, or ages past 30 seconds. A peer that reaches the client's LwM2M socket can therefore start three block-wise writes on three distinct object paths with the CoAP More bit set and leave them incomplete, then send the first block of a fourth write on a new path to reach the unguarded dereference. Reachability is gated only by the connected UDP socket's source-address filter unless CONFIG_LWM2M_DTLS_SUPPORT is enabled β€” which has no default β€” so in a NoSec deployment an on-path or address-spoofing attacker needs no credentials; the same sequence is also reachable from a bootstrap or lower-trust server, and can be hit accidentally by a legitimate server running four concurrent block transfers. The write targets a fixed low address with a value between 0 and 7, so the consequence is a fatal memory fault (BusFault or corrupted low memory leading to a fault) rather than a usable memory-corruption primitive: the device crashes or resets. Confidentiality and integrity are not affected. The fix moves the store below the guard and validates the context pointer itself instead of the return code, so the context is only touched once it is known to be valid.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zephyrproject zephyr From 3.7.0 (inc) to 4.4.2 (inc)
zephyrproject zephyr 4.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-18746 is a NULL pointer dereference vulnerability in the Zephyr RTOS LwM2M client. It occurs in the parse_write_op() function when handling CoAP WRITE/CREATE requests with a Block1 option. The function calls init_block_ctx() to allocate a block context but dereferences the returned pointer before checking if allocation succeeded. If the static block1_contexts[] pool (default size 3) is exhausted, init_block_ctx() returns -ENOMEM and leaves the pointer NULL. The code then attempts to write to this NULL pointer, causing a crash.

Detection Guidance

Detecting this vulnerability requires checking if your Zephyr RTOS LwM2M client is running a vulnerable version and monitoring for crashes or faults during CoAP Block1 operations. Inspect the LwM2M subsystem logs for NULL pointer dereference errors or BusFault/HardFault events during CoAP WRITE/CREATE requests with Block1 options. Ensure the block1_contexts pool is not exhausted by checking concurrent block transfers.

Impact Analysis

This vulnerability can cause a denial of service by crashing the device or causing undefined behavior. An attacker can remotely exploit it without authentication in NoSec deployments or from a compromised server. The device may reset or become unresponsive, but confidentiality and integrity are not affected.

Compliance Impact

This vulnerability primarily causes denial of service by crashing devices, which may impact availability requirements in compliance standards like GDPR (data availability) and HIPAA (system availability). Confidentiality and integrity are not affected, so direct violations of GDPR or HIPAA are unlikely unless availability failures lead to secondary compliance issues.

Mitigation Strategies

Upgrade to Zephyr RTOS v4.5.0 or later to apply the patch. If upgrading is not immediately possible, disable LwM2M block-wise transfers by setting CONFIG_LWM2M_BLOCK1_CONTEXT_COUNT to 0 or disable the LwM2M subsystem entirely. Enable DTLS support (CONFIG_LWM2M_DTLS_SUPPORT) to require authentication and prevent unauthenticated attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18746. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart