Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-11812— UpdateHub: race condition on shared context causes out-of-bounds write and DoS

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.0.0版本至4.4.1版本存在竞争条件问题漏洞,该漏洞源于对ctx访问未进行序列化,prepare_fds()函数写入ctx.fds时缺少边界检查,存在竞争条件,可能导致更新子系统内部状态损坏和固件更新路径拒绝服务。

CVSS 2.5 · Low EPSS 0.10% · P1

Possible ATT&CK Techniques 2 AI

T1562.001 T1564.004 · NTFS File Attributes

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 2.0.0< 4.4.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-11812

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UpdateHub: race condition on shared context causes out-of-bounds write and DoS
Source: CVE Program / CVE List V5
Vulnerability Description
The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single file-scope ctx structure that holds the CoAP block context, payload buffer, status code, socket, and a one-element poll-fd array fds[1]. Access to ctx was not serialized, and prepare_fds() wrote ctx.fds[ctx.nfds] and incremented ctx.nfds with no bounds check. Two independent paths mutate ctx concurrently: the background autohandler running on the system workqueue, and user-triggered operations reached through the updatehub run shell command, direct API calls, or — since the operations are exposed as syscalls — userspace threads. When a second flow enters prepare_fds() while ctx.nfds is already 1, the write lands one element past the array; by struct layout it overlaps the adjacent ctx.sock/ctx.nfds members. More broadly, the unsynchronized sharing lets two flows interleave connection setup and teardown, double-closing a socket descriptor or scribbling the shared buffers. The result is corruption of the update subsystem's internal state and denial of service of the firmware-update path; the out-of-bounds write is contained within the ctx structure and there is no demonstrated path to memory outside it or to code execution. Triggering requires a local actor able to invoke update operations (or, with CONFIG_USERSPACE, an unprivileged userspace thread) and to win a timing race against the background handler; remote peers cannot control the race timing. The fix serializes the entry points with a mutex and adds a bounds check to prepare_fds().
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: CVE Program / CVE List V5
Vulnerability Title
zephyrproject zephyr 竞争条件问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.0.0版本至4.4.1版本存在竞争条件问题漏洞,该漏洞源于对ctx访问未进行序列化,prepare_fds()函数写入ctx.fds时缺少边界检查,存在竞争条件,可能导致更新子系统内部状态损坏和固件更新路径拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 2.0.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-11812

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-11812

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-11812 (1)

Vendor Advisories for CVE-2026-11812 (1)

Same Patch Batch · zephyrproject · 2026-08-10 · 5 CVEs total

CVE-2026-8718 8.4 HIGH Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Z
CVE-2026-11810 7.5 HIGH NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS)
CVE-2026-11809 3.7 LOW UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata
CVE-2026-11811 3.7 LOW Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resourc

IV. Related Vulnerabilities

V. Comments for CVE-2026-11812

No comments yet


Leave a comment