CVE-2026-18417

Source
https://cve.org/CVERecord?id=CVE-2026-18417
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18417.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18417
Aliases
  • GHSA-p8r8-8mw8-3wf9
Published
2026-09-28T23:25:23Z
Modified
2026-10-06T07:05:09Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket reports an asynchronous error
Details

The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_connected_cb() and zsock_close_ctx() in subsys/net/lib/sockets/sockets_inet.c), reading it back with POINTER_TO_INT(). That same field is owned by the network stack for listening TCP contexts: net_tcp_accept() stores the parent context pointer there and the TCP core passes it back to the registered accept callback. A failed accept therefore left a small integer (an errno value) where the stack expected a struct net_context .

When the network interface carrying a listening TCP socket goes down, close_tcp_conn() in subsys/net/ip/tcp.c invokes the accept callback with -ENETDOWN and the context's user_data. In v4.3.0 the callback was not disarmed afterwards, so a second interface-down event forwarded the previously stored errno to zsock_accepted_cb(), which dereferenced it as the parent context and performed several stores through it (sock_set_error()'s read-modify-write of socket_data, k_fifo_cancel_wait(&parent->recv_q)) — the crash described in the fix's commit message. v4.3.1 and v4.4.x carry a later change clearing conn->accept_cb after the error callback (269cb8823d3 on the v4.3 branch, 913fae5169425550f2364655298fceb79b320066 on main), which closes that repeat path; on those releases the poisoned cookie remains reachable only by a narrower race, a handshake completing alongside the interface-down still passing the stale cookie to k_fifo_put(&parent->accept_q, ...), and by getsockopt(SO_ERROR), which reads the field back unconditionally.

On v4.3.0 an application that keeps a listening TCP socket open across repeated link-down events is sufficient to reach the defect; the triggering condition is a network-interface state change, not attacker-supplied packet data, so the practical attacker is one able to force the link down repeatedly (for example an adjacent attacker disrupting a wireless link) or one with local/physical access. Because both the faulting address and the stored data are fixed small constants derived from the errno value, the outcome is a wild-pointer access leading to a kernel fatal error — a denial of service (device crash or reset) rather than an attacker-directed memory corruption.

The fix stores the pending error in a dedicated net_context.sock_error field and converts every producer and consumer to sock_set_error()/sock_get_error(), leaving user_data untouched. As a side effect it also stops getsockopt(SO_ERROR) — which is evaluated unconditionally — from returning the kernel address held in user_data to a userspace application.

Database specific
{
    "cna_assigner": "zephyr",
    "cwe_ids": [
        "CWE-843"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18417.json"
}
References

Affected packages

Git / github.com/zephyrproject-rtos/zephyr

Affected ranges

Type
GIT
Repo
https://github.com/zephyrproject-rtos/zephyr
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.3.0"
        },
        {
            "fixed": "4.4.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v4.*
v4.3.0
v4.4.0
v4.4.0-rc1
v4.4.0-rc2
v4.4.0-rc3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18417.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "249757351194692060153143896325047353203",
            "length": 620
        },
        "id": "CVE-2026-18417-251c3f43",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c",
            "function": "zsock_accepted_cb"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "17855606263115039085277308931834397137",
            "length": 236
        },
        "id": "CVE-2026-18417-2aade1c0",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c",
            "function": "zsock_connected_cb"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "275206462627606949070060556519625581779",
            "length": 1491
        },
        "id": "CVE-2026-18417-407325b4",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c",
            "function": "zsock_connect_ctx"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "173428397155914906857095599647928295383",
            "length": 7283
        },
        "id": "CVE-2026-18417-5041d9aa",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c",
            "function": "zsock_getsockopt_ctx"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "336125572198177618939679228891155349146",
            "length": 1524
        },
        "id": "CVE-2026-18417-53f39ee5",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c",
            "function": "zsock_recv_stream_timed"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "328285279886879761799504266925994698633",
            "length": 914
        },
        "id": "CVE-2026-18417-869318cc",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c",
            "function": "zsock_accept_ctx"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "96670145089230063509703961541662844479",
                "151973363514319119142074886778856523318",
                "146283290681606748997627674994023846630",
                "321230317995698414128398369873544048673",
                "9754207811913037057534215439383653822",
                "35613814245707601930691286850530287336",
                "210035013191358789791254575426304321024",
                "105403391115751245557572799662891998835",
                "120073532724935891565493583535821176984",
                "126742317068102497649821823808140583787",
                "191386033358588105802450080948687508351",
                "131927287623992668775506378994391583660",
                "155338932707214857544045926619263852401",
                "251647036278631537318243079811930513947",
                "47964996117417545156109357130815827244",
                "120250472741880214215663548902922522036",
                "297226932718279669162723882532720096189",
                "245571697378577249229137554426881859999",
                "167824643550752417074122292199431356046",
                "23145884134910986135750279514287242202",
                "285237642213976634117665899926459772131",
                "134402979617327092929615926571585379868",
                "293888024150182888761506921845432426320",
                "32869673677368490031637610454239661337",
                "117356585375301013237150668647018461166",
                "299956473271434463879157877716197250813",
                "158858269766967679188559913657111469959",
                "56603969567321320206698660312042525712",
                "151424923543472649243754549078645506329",
                "138869026226837696737363858625500751520",
                "39770127941192461788126273494737622279",
                "294463105455184646380548403744679010446",
                "38938250988128238285796125120514274057",
                "46457952889260312352745971307806846079",
                "157267685603492005707157526984953280634",
                "40146496363208111796002438181380559304",
                "166258738287616709019706899963457612631",
                "156823703597013903919258122699115022283",
                "252583066329374826517772577462253949037",
                "231044846504627601291158687254780776470"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-18417-89877b19",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "282520286835445350101269198315176298469",
                "269800403021565680910096290133993646739",
                "83415755108879061082188902057190655799"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-18417-8e258bbb",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_internal.h"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "183978121340813154249710392297435561644",
            "length": 618
        },
        "id": "CVE-2026-18417-b7d237a9",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c",
            "function": "zsock_close_ctx"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "75193067994208300940554692176814744500",
            "length": 1073
        },
        "id": "CVE-2026-18417-bb416a75",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c",
            "function": "zsock_received_cb"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "193889201903867902937476103172604800125",
            "length": 417
        },
        "id": "CVE-2026-18417-cbcde105",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "subsys/net/lib/sockets/sockets_inet.c",
            "function": "zsock_wait_data"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "4181058407619802964264343341766351765",
                "101499530781924718518890346974627861783",
                "95263714653883004058648010219398960120"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-18417-efed8a99",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54",
        "target": {
            "file": "include/zephyr/net/net_context.h"
        }
    }
]
vanir_signatures_modified
"2026-10-06T07:05:09Z"