Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-11811— Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.0.0版本至4.4.2之前版本存在资源管理错误漏洞,该漏洞源于subsys/mgmt/updatehub/updatehub.c文件中的start_coap_client()函数在连接建立失败路径上泄漏CoAP/DTLS套接字描述符,由于错误处理中ret标志设置不当导致清理函数未被调用,攻击者可通过网络干扰连接触发,造成套接字/net_contex

CVSS 3.7 · Low EPSS 0.40% · P32

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 2.0.0< 4.4.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-11811

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS
Source: CVE Program / CVE List V5
Vulnerability Description
The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when zsock_setsockopt() (DTLS) or zsock_connect() subsequently failed the gate was false and cleanup_connection() was never called. The open descriptor in the global ctx.sock was then overwritten by the next attempt, permanently leaking it from the socket / net_context pool until reboot. The failing setup path is reached every time the OTA client tries to contact the UpdateHub server and the connection cannot be established — driven automatically by the periodic autohandler() poll (and on demand via the updatehub_probe()/updatehub_update() API or the updatehub run shell command). The DTLS handshake/connect outcome is influenceable by a network or on-path attacker who drops, resets, or otherwise disrupts traffic to the server, and also fails naturally whenever the server is unreachable. Each failed attempt permanently leaks one descriptor; once the shared socket pool is exhausted, networking degrades device-wide until the device is rebooted, a denial-of-service condition. Severity is low because the leak rate is bounded by the configured OTA poll interval (default once per 24 hours), the effect is gradual and recovered by reboot, and only builds with the UpdateHub client enabled are affected. There is no memory-corruption, information-disclosure, or authentication impact.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对已超过有效生命周期的资源丧失索引
Source: CVE Program / CVE List V5
Vulnerability Title
zephyrproject zephyr 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.0.0版本至4.4.2之前版本存在资源管理错误漏洞,该漏洞源于subsys/mgmt/updatehub/updatehub.c文件中的start_coap_client()函数在连接建立失败路径上泄漏CoAP/DTLS套接字描述符,由于错误处理中ret标志设置不当导致清理函数未被调用,攻击者可通过网络干扰连接触发,造成套接字/net_contex
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 2.0.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-11811

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-11811

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-11811 (1)

Vendor Advisories for CVE-2026-11811 (1)

Same Patch Batch · zephyrproject · 2026-08-10 · 5 CVEs total

CVE-2026-8718 8.4 HIGH Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Z
CVE-2026-11810 7.5 HIGH NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS)
CVE-2026-11809 3.7 LOW UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata
CVE-2026-11812 2.5 LOW UpdateHub: race condition on shared context causes out-of-bounds write and DoS

IV. Related Vulnerabilities

V. Comments for CVE-2026-11811

No comments yet


Leave a comment