Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-10663— Use-after-free / double-free of the root USB device in the experimental USB host stack

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 Zephyr Project Zephyr 4.4.0版本及4.5.0之前版本存在资源管理错误漏洞,该漏洞源于USB主机堆栈中usbh_device_disconnect()函数未清除缓存指针ctx->root,导致释放后重用和双重释放,攻击者可通过物理USB访问触发拒绝服务和内存破坏。

CVSS 6.1 · Medium EPSS 0.24% · P13

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 4.4.0< 4.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10663

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Use-after-free / double-free of the root USB device in the experimental USB host stack
Source: CVE Program / CVE List V5
Vulnerability Description
In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device slab object without clearing the cached pointer ctx->root. The bus removal handler dev_removed_handler() (subsys/usb/host/usbh_core.c) decides what to tear down solely from ctx->root, checking only that it is non-NULL. Because UHC controller drivers (e.g. uhc_max3421e, uhc_mcux_common) synthesize UHC_EVT_DEV_REMOVED directly from physical bus line state with no debounce or state guard, an attacker with physical USB access (or a rogue device that bounces its connection) can deliver a second device-removed event after a root device disconnect. The handler then re-enters usbh_device_disconnect() with the dangling pointer, locking a mutex inside the freed object (use-after-free), removing the freed node from the device list, and calling k_mem_slab_free() on the already-freed block (double-free). If the slab block has been reissued to a newly attached device in between, this corrupts a live object. Impact is denial of service (crash) and memory corruption; the attack vector is physical/local. The flaw was introduced in v4.4.0 by the connect/disconnect refactor and is fixed by clearing ctx->root in usbh_device_disconnect() before freeing.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5
Vulnerability Title
Zephyr Project Zephyr 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 Zephyr Project Zephyr 4.4.0版本及4.5.0之前版本存在资源管理错误漏洞,该漏洞源于USB主机堆栈中usbh_device_disconnect()函数未清除缓存指针ctx->root,导致释放后重用和双重释放,攻击者可通过物理USB访问触发拒绝服务和内存破坏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 4.4.0 ~ 4.5.0 -

II. Public POCs for CVE-2026-10663

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10663

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-10663 (1)

Vendor Advisories for CVE-2026-10663 (1)

Same Patch Batch · zephyrproject · 2026-07-12 · 6 CVEs total

CVE-2026-10666 8.1 HIGH Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/ne
CVE-2026-10667 7.8 HIGH SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable
CVE-2026-10665 7.4 HIGH Heap buffer overflow on WireGuard receive path via unbounded incoming packet length
CVE-2026-10664 5.0 MEDIUM Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow cou
CVE-2026-10668 2.4 LOW Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver

IV. Related Vulnerabilities

V. Comments for CVE-2026-10663

No comments yet


Leave a comment