Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-10672— Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyrproject zephyr存在缓冲区错误漏洞,该漏洞源于lwm2m_pull_context.c将固件更新包URI复制到固定静态缓冲区时未进行长度验证,可能导致相邻静态内存的越界读取,进而造成信息泄露和拒绝服务。以下版本受到影响:3.0.0至4.4.0版本。

CVSS 8.2 · High EPSS 0.58% · P46

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 3.0.0< 4.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10672

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)
Source: CVE Program / CVE List V5
Vulnerability Description
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.uri, uri, LWM2M_PACKAGE_URI_LEN), copying exactly the destination size with no length validation. The Firmware-Update object stores the server-supplied Package URI (/5/0/1) in a 255-byte buffer, so a LwM2M management server (or an on-path attacker on a session lacking strong DTLS) can WRITE a URI of 128-254 characters; only the first 128 bytes are then copied into context.uri with no NUL terminator. That buffer is subsequently consumed as a C string by http_parser_parse_url(context.uri, strlen(context.uri), ...), strlen-based CoAP URI-path/PROXY-URI option appends, and lwm2m_parse_peerinfo(), causing an out-of-bounds read of adjacent static memory. The over-read bytes are appended to outbound CoAP requests (information disclosure of adjacent device memory to the server/proxy) and can crash the device (denial of service). The vulnerable copy was introduced by the pull-context refactor (first released in v3.0.0) and is present through v4.4.0; the default-on CONFIG_LWM2M_FIRMWARE_UPDATE_PULL_SUPPORT path is affected. The fix adds a strlen(uri) >= sizeof(context.uri) check returning -ENOMEM and switches to strcpy(), guaranteeing a bounded, NUL-terminated buffer.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5
Vulnerability Title
zephyrproject zephyr 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyrproject zephyr存在缓冲区错误漏洞,该漏洞源于lwm2m_pull_context.c将固件更新包URI复制到固定静态缓冲区时未进行长度验证,可能导致相邻静态内存的越界读取,进而造成信息泄露和拒绝服务。以下版本受到影响:3.0.0至4.4.0版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 3.0.0 ~ 4.5.0 -

II. Public POCs for CVE-2026-10672

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10672

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-10672 (1)

Vendor Advisories for CVE-2026-10672 (1)

Same Patch Batch · zephyrproject · 2026-07-14 · 4 CVEs total

CVE-2026-10669 7.8 HIGH Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall poi
CVE-2026-10671 7.1 HIGH User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_U
CVE-2026-10670 5.5 MEDIUM User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall v

IV. Related Vulnerabilities

V. Comments for CVE-2026-10672

No comments yet


Leave a comment