Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12234— TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.3.0版本至4.4.2之前版本存在竞争条件问题漏洞,该漏洞源于用户态系统调用验证器z_vrfy_zsock_sendmsg()和z_vrfy_zsock_recvmsg()存在双重获取/TOCTOU竞争条件,可能导致本地权限提升或拒绝服务。

CVSS 7.8 · High EPSS 0.11% · P1

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 2.3.0< 4.4.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12234

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write
Source: CVE Program / CVE List V5
Vulnerability Description
The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-live user struct for subsequent decisions. The kernel iovec shadow buffer is sized from one read of msg->msg_iovlen, while the population loop is bounded by a second, live read of the same field. Because msg points into ordinary user memory, a cooperating second thread in the same memory domain can inflate msg->msg_iovlen in the window between the sizing read and the loop test (a classic double-fetch / TOCTOU). The population loop then iterates past the number of net_iovec slots actually allocated, writing attacker-influenced iov_base/iov_len values beyond the end of the kernel-heap shadow buffer. The recvmsg verifier has the same defect on both its inbound and result write-back loops. The code is reachable from an unprivileged user thread whenever CONFIG_USERSPACE is enabled and the zsock_sendmsg/zsock_recvmsg syscalls are available. A successful race corrupts kernel-managed heap memory across the user-to-kernel privilege boundary, yielding a local privilege-escalation primitive or, at minimum, a kernel-fault denial of service. The fix copies the header once and derives every size, bound, and gate from the snapshot, copying each iovec entry atomically so its base and length can no longer be raced apart.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5
Vulnerability Title
zephyrproject zephyr 竞争条件问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.3.0版本至4.4.2之前版本存在竞争条件问题漏洞,该漏洞源于用户态系统调用验证器z_vrfy_zsock_sendmsg()和z_vrfy_zsock_recvmsg()存在双重获取/TOCTOU竞争条件,可能导致本地权限提升或拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 2.3.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-12234

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12234

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-12234 (1)

Vendor Advisories for CVE-2026-12234 (1)

Same Patch Batch · zephyrproject · 2026-08-12 · 4 CVEs total

CVE-2026-12235 6.3 MEDIUM Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787)
CVE-2026-12232 6.1 MEDIUM Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties
CVE-2026-12233 5.9 MEDIUM Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under c

IV. Related Vulnerabilities

V. Comments for CVE-2026-12234

No comments yet


Leave a comment