CVE-2026-18747
Received Received - Intake

Buffer Overflow in MCUmgr SMP-over-console Transport

Vulnerability report for CVE-2026-18747, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Zephyr Project

Description

The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/mcumgr/transport/src/serial_util.c). mcumgr_serial_extract_len() accepted any declared length, including 0 and 1, and a packet declaring length 0 passes the checksum test for free because crc16_itu_t() over zero bytes returns the zero seed. Since net_buf::len is a uint16_t, the subtraction underflows and the buffer is handed to SMP claiming roughly 65 KB of payload while its data area is only CONFIG_MCUMGR_TRANSPORT_NETBUF_SIZE bytes (default 384). The trigger is a single unauthenticated 7-byte line on the management console β€” the 0x06 0x09 packet marker followed by the base64 group AAA= and a newline β€” delivered to any transport built on this helper: CONFIG_MCUMGR_TRANSPORT_UART (smp_uart.c) or CONFIG_MCUMGR_TRANSPORT_SHELL (smp_shell.c), both of which select MCUMGR_TRANSPORT_SERIAL_HAS_SMP_OVER_CONSOLE. No prior session state, fragmentation or credentials are required to trigger the underflow, and the malformed frame is mishandled before any command handler or command-level access control runs. The attacker only needs write access to that console, which on many boards is a USB CDC-ACM port rather than a bare UART header. With the inflated length, smp_process_request_packet() in subsys/mgmt/mcumgr/smp/src/smp.c loses its bound: cbor_nb_reader_init() gives the CBOR decoder a ~65 KB window into a 384-byte buffer, and each request header's nh_len is checked only against the inflated length. On its own the 7-byte frame re-parses whatever stale bytes the reused pool buffer still holds, typically a replay of the previously received request followed by a parse error, without leaving the buffer. Because the transport is unauthenticated, though, the attacker also controls the frames sent before the trigger, and can stage buffer contents so that a request succeeds with an nh_len larger than the buffer; net_buf_pull(), guarded only by __ASSERT_NO_MSG, then moves the parse cursor out of bounds and the loop reads further headers and CBOR from adjacent memory. The consequence is an out-of-bounds read that can fault the MCUmgr thread (denial of service); memory disclosure is also possible, since the default-enabled os echo handler (CONFIG_MCUMGR_GRP_OS_ECHO) decodes its string inside that window and copies it into its response. There is no integrity gain beyond what the unauthenticated transport already permits. The fix rejects any declared packet length of two bytes or fewer in mcumgr_serial_extract_len(), so the CRC-strip subtraction can no longer underflow. The identical pattern remains in the test-only loopback transport subsys/mgmt/mcumgr/transport/src/smp_dummy.c (CONFIG_MCUMGR_TRANSPORT_DUMMY), which has no external input path and therefore carries no practical exposure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
nordic_semi mcumgr *
zephyrproject zephyr *
nordic_semi zephyr From 1.11.0 (inc) to 4.4.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer underflow in the MCUmgr serial transport of Zephyr RTOS. It occurs when a 16-bit packet length is read from a base64-decoded frame, verified with a CRC, and then reduced by 2 bytes to strip the CRC. If the declared packet length is 0 or 1, the CRC check passes, and the subtraction underflows the buffer length, causing it to wrap to a large value like 65534. This inflated length is then passed to the SMP layer, which interprets the buffer as containing up to ~65 KB of data, far exceeding the actual buffer size of 384 bytes.

Detection Guidance

Detecting this vulnerability requires checking if your system uses MCUmgr with SMP-over-console transport. Inspect the serial console or USB CDC-ACM port for unauthenticated 7-byte frames like 0x06 0x09 AAA= followed by a newline. Monitor for crashes or memory disclosure in the MCUmgr thread.

Impact Analysis

The vulnerability allows an attacker with write access to the management console (often a USB CDC-ACM port) to send a single 7-byte frame to trigger the underflow. This can lead to an out-of-bounds read, potentially causing a denial of service or memory disclosure. The default echo handler can also copy malformed data into responses, further exposing memory.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it pertains to data processing or storage. However, it could indirectly impact compliance by enabling unauthorized access to memory contents (memory disclosure) or causing denial of service, which may violate principles of data integrity and availability required by these regulations.

Mitigation Strategies

Apply the patch from the Zephyr RTOS commit f7fc3e779a59c68c96eaf63a6b03ac7489f5e4a5. Disable unauthenticated serial console access if possible. Ensure the MCUmgr transport validates packet lengths strictly to prevent underflow.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18747. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart