Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-10655— Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it

CVSS 6.5 · Medium EPSS 0.30% · P23

Possible ATT&CK Techniques 1AI

T1498 · Network Denial of Service

Affected Version Matrix 1

VendorProductVersion RangeStatus
zephyrprojectzephyr4.2.0< 4.5.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-10655

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it
Source: CVE Program / CVE List V5
Vulnerability Description
The asynchronous SNTP client in Zephyr (subsys/net/lib/sntp/sntp.c, sntp_close_async) closed the UDP socket file descriptor directly from the calling thread immediately after detaching it from the network socket service, without synchronizing with the socket-service poll thread. The socket service thread polls each socket via zvfs_poll, which (in zsock_poll_prepare_ctx) registers a k_poll_event pointing into the socket's net_context (&ctx->recv_q) and then blocks in k_poll without holding a reference or lock. net_context objects are allocated from a fixed pool (contexts[CONFIG_NET_MAX_CONTEXTS]) and reused after close. When sntp_close_async is invoked from a different thread than the poll thread (in the in-tree consumer subsys/net/lib/config/init_clock_sntp.c, the SNTP timeout handler runs on the system workqueue while the socket service thread is blocked in poll on the same fd), the close frees and may reuse the net_context while the poll thread still has a poller node linked into the freed object, resulting in a use-after-free / object confusion of kernel poll structures. The SNTP timeout path is the normal no-response failure mode, so a network peer or off-path attacker who drops or delays the SNTP/NTP response can drive the racing close repeatedly (and periodically with NET_CONFIG_SNTP_INIT_RESYNC). The most likely consequence is a crash of the networking thread (denial of service), with potential memory corruption when the freed context slot is reallocated. The fix defers the close to the socket service thread itself via net_socket_service_close (NET_SOCKET_SERVICE_CLOSE_SOCKETS), so the same thread that polls performs the close, eliminating the race. Affected releases: v4.2.0 through v4.4.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5
Vulnerability Title
Zephyr 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Zephyr是Zephyr组织开源的一个可扩展的实时操作系统 (RTOS)。 Zephyr 4.2.0版本至4.4.0版本存在资源管理错误漏洞,该漏洞源于SNTP客户端在关闭UDP套接字文件描述符时未与套接字服务轮询线程同步,导致释放后重用,可能造成内核轮询结构对象混淆,攻击者通过丢弃或延迟SNTP/NTP响应可重复触发竞争,最可能导致网络线程崩溃(拒绝服务)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
zephyrprojectzephyr 4.2.0 ~ 4.5.0 -

II. Public POCs for CVE-2026-10655

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10655

登录查看更多情报信息。

Patches & Fixes for CVE-2026-10655 (1)

Vendor Advisories for CVE-2026-10655 (1)

Same Patch Batch · zephyrproject · 2026-06-30 · 5 CVEs total

CVE-2026-92636.5 MEDIUMOut-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memor
CVE-2026-106536.4 MEDIUMNon-atomic `net_buf` reference counts cause double-free / free-list corruption under concu
CVE-2026-106524.8 MEDIUMOut-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)
CVE-2026-106543.1 LOWRFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Ze

IV. Related Vulnerabilities

V. Comments for CVE-2026-10655

No comments yet


Leave a comment