CVE-2026-12051

Source
https://cve.org/CVERecord?id=CVE-2026-12051
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12051.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-12051
Aliases
  • GHSA-vhvq-q6rw-jvm4
Published
2026-08-11T05:31:19Z
Modified
2026-09-02T08:05:45Z
Severity
  • 4.6 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
NULL pointer dereference in USB DFU device_next download handler (handle_download)
Details

The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes MIN(setup->wLength, buf->len) and passes buf->data to the image write callback without checking that the buf net_buf pointer is non-NULL.

The handler is reached over the USB control endpoint, driven by the USB host. For a DFU_DNLOAD (download) request with no Data OUT stage — notably the zero-length terminating download that the DFU protocol uses to end a firmware transfer — the USB core invokes the class handler with a NULL buffer. After the device has been advanced to the DFU_DNLOAD_IDLE state (by sending one valid download block and a GET_STATUS), a zero-length DFU_DNLOAD reaches handle_download() with buf == NULL, dereferencing it.

The result is a NULL+offset read that triggers a fatal CPU fault, i.e. a denial of service (device crash/reset). The attacker is whatever controls the USB host the device is attached to; DFU download support must be enabled with a registered image. There is no memory corruption or information disclosure — impact is limited to availability. The fix adds an explicit if (buf != NULL) guard so the callback receives a zero-length, NULL-data transfer instead of crashing.

Database specific
{
    "cna_assigner": "zephyr",
    "cwe_ids": [
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12051.json"
}
References

Affected packages

Git / github.com/zephyrproject-rtos/zephyr

Affected ranges

Type
GIT
Repo
https://github.com/zephyrproject-rtos/zephyr
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.4.0"
        },
        {
            "fixed": "4.4.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v4.*
v4.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12051.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "51695995382540564724771539224986601309",
                "234033040335975934430491510740375948573",
                "261489404340916789900145769588812295340",
                "106914763439782829593453702443344437153",
                "41266411084202754488436768641405680276",
                "315809052901959911278253377441048002412"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-12051-5ffcdca5",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/552ca371257597b71490482d5cc597157ea60f12",
        "target": {
            "file": "subsys/usb/device_next/class/usbd_dfu.c"
        }
    }
]
vanir_signatures_modified
"2026-09-02T08:05:45Z"