In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock.
On SMP systems, two user-mode threads invoking the k_object_alloc(K_OBJ_THREAD) syscall concurrently can both observe the same low free bit, perform the same non-atomic RMW to clear it, and return the identical tidx.
The two newly created K_OBJ_THREAD objects are then assigned the same thread_id, so the two user threads alias a single bit position in every kernel object's perms[] bitfield: any subsequent grant of access on a kernel object to one thread is implicitly a grant to the other, defeating userspace ACL isolation. A secondary lost-update window between the unlocked &=~BIT() in alloc and the locked |= BIT() in thread_idx_free() can also leak entries from the thread-index pool.
The defect is reachable from any user-mode thread via the unrestricted __syscall k_object_alloc and is gated on CONFIG_USERSPACE, CONFIG_DYNAMIC_OBJECTS, and CONFIG_SMP. The flaw was introduced when the per-thread permission index was added in 2018 and is present in every release up to and including v4.4.0. Fixed by holding lists_lock across the bitmap RMW and the permissions clear (and inlining the obj_list traversal that previously took the lock itself).
{
"cna_assigner": "zephyr",
"cwe_ids": [
"CWE-362"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10681.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2.0.0"
},
{
"fixed": "4.5.0"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10681.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"254181256075881528711393979358624856114",
"186009842249674552281360155679655173022",
"117347246642953266906332931228841015214",
"132448529765873880255758202364819989928",
"212207850221374485388977835359508477483",
"160614631444464157187253622538401180114",
"174911220827669003474855520921071468440",
"236663377150407247951460968666871715667",
"129379878140685239303749708640375592243",
"27117102453365665485112606865773598709",
"231833741669393908675587623467326188434",
"232697874355205015241178692648507298122",
"200174929943578556159533706904550089386",
"42063907391132923437362319218619461438",
"131722512003846867279772610515639023788",
"153665716785748737967907692323276887497",
"7912376822815440744228825108403110472"
],
"threshold": 0.9
},
"id": "CVE-2026-10681-24fc6682",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/862ea2fbbeb2ccdf8ff994b03e2e3b4405f2c37d",
"target": {
"file": "kernel/userspace/userspace.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "298964898953416431060340742891111629021",
"length": 393
},
"id": "CVE-2026-10681-aff312eb",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/862ea2fbbeb2ccdf8ff994b03e2e3b4405f2c37d",
"target": {
"file": "kernel/userspace/userspace.c",
"function": "thread_idx_alloc"
}
}
]
"2026-08-12T15:31:11Z"