Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-10677— Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyrproject Zephyr 1.12.0版本至4.4.1版本存在资源管理错误漏洞,该漏洞源于内核中的CONFIG_USERSPACE系统调用验证器z_vrfy_k_poll()在验证用户提供的k_poll_event[]时分配内核侧副本后未能释放内存,可能导致用户线程通过伪造对象句柄并重复泄漏分配来耗尽共享内核堆,从而造成系统级拒绝服务。

CVSS 6.5 · Medium EPSS 0.14% · P3

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 1.12.0< 4.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10677

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool
Source: CVE Program / CVE List V5
Vulnerability Description
The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_poll_event[] via z_thread_malloc() and then validates each event's object handle. Before this fix, validation used K_OOPS(K_SYSCALL_OBJ(...)) inline inside the loop, which kills the calling thread without freeing events_copy. A user thread can pass num_events >= 1 with a forged object handle to leak the allocation; because newly spawned user threads inherit the parent's resource_pool (kernel/thread.c), an attacker spawns sacrificial threads to repeat the leak until the shared kernel heap is exhausted. Once depleted, legitimate kernel allocations from that pool (k_queue alloc nodes, k_msgq buffers, future k_poll calls, etc.) fail, causing a system-level denial of service. The fix replaces each inline K_OOPS with a conditional goto oops_free so the buffer is freed before the thread is killed. Affects Zephyr releases from v1.12.0 (when k_poll was first exposed to user mode) through v4.4.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在移除最后引用时对内存的释放不恰当(内存泄露)
Source: CVE Program / CVE List V5
Vulnerability Title
zephyrproject zephyr 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyrproject Zephyr 1.12.0版本至4.4.1版本存在资源管理错误漏洞,该漏洞源于内核中的CONFIG_USERSPACE系统调用验证器z_vrfy_k_poll()在验证用户提供的k_poll_event[]时分配内核侧副本后未能释放内存,可能导致用户线程通过伪造对象句柄并重复泄漏分配来耗尽共享内核堆,从而造成系统级拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 1.12.0 ~ 4.5.0 -

II. Public POCs for CVE-2026-10677

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10677

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-10677 (1)

Vendor Advisories for CVE-2026-10677 (1)

Same Patch Batch · zephyrproject · 2026-07-21 · 6 CVEs total

CVE-2026-10678 8.1 HIGH NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an una
CVE-2026-10680 7.6 HIGH Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t`
CVE-2026-10674 5.5 MEDIUM DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disab
CVE-2026-10675 4.3 MEDIUM Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re
CVE-2026-10679 3.3 LOW Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)

IV. Related Vulnerabilities

V. Comments for CVE-2026-10677

No comments yet


Leave a comment