The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_connected_cb() and zsock_close_ctx() in subsys/net/lib/sockets/sockets_inet.c), reading it back with POINTER_TO_INT(). That same field is owned by the network stack for listening TCP contexts: net_tcp_accept() stores the parent context pointer there and the TCP core passes it back to the registered accept callback. A failed accept therefore left a small integer (an errno value) where the stack expected a struct net_context .
When the network interface carrying a listening TCP socket goes down, close_tcp_conn() in subsys/net/ip/tcp.c invokes the accept callback with -ENETDOWN and the context's user_data. In v4.3.0 the callback was not disarmed afterwards, so a second interface-down event forwarded the previously stored errno to zsock_accepted_cb(), which dereferenced it as the parent context and performed several stores through it (sock_set_error()'s read-modify-write of socket_data, k_fifo_cancel_wait(&parent->recv_q)) — the crash described in the fix's commit message. v4.3.1 and v4.4.x carry a later change clearing conn->accept_cb after the error callback (269cb8823d3 on the v4.3 branch, 913fae5169425550f2364655298fceb79b320066 on main), which closes that repeat path; on those releases the poisoned cookie remains reachable only by a narrower race, a handshake completing alongside the interface-down still passing the stale cookie to k_fifo_put(&parent->accept_q, ...), and by getsockopt(SO_ERROR), which reads the field back unconditionally.
On v4.3.0 an application that keeps a listening TCP socket open across repeated link-down events is sufficient to reach the defect; the triggering condition is a network-interface state change, not attacker-supplied packet data, so the practical attacker is one able to force the link down repeatedly (for example an adjacent attacker disrupting a wireless link) or one with local/physical access. Because both the faulting address and the stored data are fixed small constants derived from the errno value, the outcome is a wild-pointer access leading to a kernel fatal error — a denial of service (device crash or reset) rather than an attacker-directed memory corruption.
The fix stores the pending error in a dedicated net_context.sock_error field and converts every producer and consumer to sock_set_error()/sock_get_error(), leaving user_data untouched. As a side effect it also stops getsockopt(SO_ERROR) — which is evaluated unconditionally — from returning the kernel address held in user_data to a userspace application.
{
"cna_assigner": "zephyr",
"cwe_ids": [
"CWE-843"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18417.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18417.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "249757351194692060153143896325047353203",
"length": 620
},
"id": "CVE-2026-18417-251c3f43",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c",
"function": "zsock_accepted_cb"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "17855606263115039085277308931834397137",
"length": 236
},
"id": "CVE-2026-18417-2aade1c0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c",
"function": "zsock_connected_cb"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "275206462627606949070060556519625581779",
"length": 1491
},
"id": "CVE-2026-18417-407325b4",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c",
"function": "zsock_connect_ctx"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "173428397155914906857095599647928295383",
"length": 7283
},
"id": "CVE-2026-18417-5041d9aa",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c",
"function": "zsock_getsockopt_ctx"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "336125572198177618939679228891155349146",
"length": 1524
},
"id": "CVE-2026-18417-53f39ee5",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c",
"function": "zsock_recv_stream_timed"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "328285279886879761799504266925994698633",
"length": 914
},
"id": "CVE-2026-18417-869318cc",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c",
"function": "zsock_accept_ctx"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"96670145089230063509703961541662844479",
"151973363514319119142074886778856523318",
"146283290681606748997627674994023846630",
"321230317995698414128398369873544048673",
"9754207811913037057534215439383653822",
"35613814245707601930691286850530287336",
"210035013191358789791254575426304321024",
"105403391115751245557572799662891998835",
"120073532724935891565493583535821176984",
"126742317068102497649821823808140583787",
"191386033358588105802450080948687508351",
"131927287623992668775506378994391583660",
"155338932707214857544045926619263852401",
"251647036278631537318243079811930513947",
"47964996117417545156109357130815827244",
"120250472741880214215663548902922522036",
"297226932718279669162723882532720096189",
"245571697378577249229137554426881859999",
"167824643550752417074122292199431356046",
"23145884134910986135750279514287242202",
"285237642213976634117665899926459772131",
"134402979617327092929615926571585379868",
"293888024150182888761506921845432426320",
"32869673677368490031637610454239661337",
"117356585375301013237150668647018461166",
"299956473271434463879157877716197250813",
"158858269766967679188559913657111469959",
"56603969567321320206698660312042525712",
"151424923543472649243754549078645506329",
"138869026226837696737363858625500751520",
"39770127941192461788126273494737622279",
"294463105455184646380548403744679010446",
"38938250988128238285796125120514274057",
"46457952889260312352745971307806846079",
"157267685603492005707157526984953280634",
"40146496363208111796002438181380559304",
"166258738287616709019706899963457612631",
"156823703597013903919258122699115022283",
"252583066329374826517772577462253949037",
"231044846504627601291158687254780776470"
],
"threshold": 0.9
},
"id": "CVE-2026-18417-89877b19",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"282520286835445350101269198315176298469",
"269800403021565680910096290133993646739",
"83415755108879061082188902057190655799"
],
"threshold": 0.9
},
"id": "CVE-2026-18417-8e258bbb",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_internal.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "183978121340813154249710392297435561644",
"length": 618
},
"id": "CVE-2026-18417-b7d237a9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c",
"function": "zsock_close_ctx"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "75193067994208300940554692176814744500",
"length": 1073
},
"id": "CVE-2026-18417-bb416a75",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c",
"function": "zsock_received_cb"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "193889201903867902937476103172604800125",
"length": 417
},
"id": "CVE-2026-18417-cbcde105",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "subsys/net/lib/sockets/sockets_inet.c",
"function": "zsock_wait_data"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"4181058407619802964264343341766351765",
"101499530781924718518890346974627861783",
"95263714653883004058648010219398960120"
],
"threshold": 0.9
},
"id": "CVE-2026-18417-efed8a99",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
"target": {
"file": "include/zephyr/net/net_context.h"
}
}
]
"2026-10-06T07:05:09Z"