Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-10667— SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 Zephyr Project Zephyr 1.14.0版本至4.5.0之前版本存在资源管理错误漏洞,该漏洞源于动态内核对象跟踪中的释放后重用问题,在SMP系统中,由于列表遍历和节点释放使用不同的自旋锁,可能导致内核内存损坏,造成权限提升或内核崩溃。

CVSS 7.8 · High EPSS 0.15% · P4

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 1.14.0< 4.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10667

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads
Source: CVE Program / CVE List V5
Vulnerability Description
Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. Iteration over this list in k_object_wordlist_foreach() was performed under lists_lock using the SAFE iterator (which caches the next node), but list removal and freeing of nodes was performed under different, disjoint spinlocks: objfree_lock in k_object_free() and obj_lock in unref_check(). On an SMP system, while one CPU iterated obj_list under lists_lock, another CPU could unlink and k_free() the dyn_obj node that the iterator had cached as its next pointer, causing the iterator to dereference freed kernel memory (use-after-free / dangling list traversal). All of the racing operations are reachable from unprivileged user-mode threads via system calls: k_object_alloc/k_object_alloc_size and k_object_release drive removals through unref_check() (under obj_lock), while k_thread_abort and thread creation drive the iteration through k_thread_perms_all_clear()/k_thread_perms_inherit() (under lists_lock). A deprivileged user thread on a CONFIG_SMP + CONFIG_USERSPACE build can therefore corrupt the kernel's object-tracking structures across the userspace security boundary, yielding kernel memory corruption (potential privilege escalation) or a kernel crash (denial of service). The fix removes objfree_lock and serializes every obj_list modification under lists_lock, including holding it across find+remove in k_object_free() and around unref_check() in k_thread_perms_clear(). Affects CONFIG_SMP+CONFIG_USERSPACE+CONFIG_DYNAMIC_OBJECTS configurations; the defect dates to the 2019 spinlockification (commit 8a3d57b6cc6, first released in v1.14.0) and shipped through v4.4.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5
Vulnerability Title
Zephyr Project Zephyr 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 Zephyr Project Zephyr 1.14.0版本至4.5.0之前版本存在资源管理错误漏洞,该漏洞源于动态内核对象跟踪中的释放后重用问题,在SMP系统中,由于列表遍历和节点释放使用不同的自旋锁,可能导致内核内存损坏,造成权限提升或内核崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 1.14.0 ~ 4.5.0 -

II. Public POCs for CVE-2026-10667

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10667

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-10667 (1)

Vendor Advisories for CVE-2026-10667 (1)

Same Patch Batch · zephyrproject · 2026-07-12 · 6 CVEs total

CVE-2026-10666 8.1 HIGH Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/ne
CVE-2026-10665 7.4 HIGH Heap buffer overflow on WireGuard receive path via unbounded incoming packet length
CVE-2026-10663 6.1 MEDIUM Use-after-free / double-free of the root USB device in the experimental USB host stack
CVE-2026-10664 5.0 MEDIUM Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow cou
CVE-2026-10668 2.4 LOW Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver

IV. Related Vulnerabilities

V. Comments for CVE-2026-10667

No comments yet


Leave a comment