Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18746— NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

中的 函数在处理携带 Block1 选项的传入 CoAP WRITE/CREATE 请求时存在漏洞。在处理传输的第一个块时,该函数先调用 ,随后在检查其返回码之前,立即将客户端选择的块大小存储到 中。然而,当静态池 中没有可用条目(因空间不足或超时)时, 会将调用方的指针设置为 NULL 并返回 。因此,后续的存储操作会解引用一个 NULL 指针。 该池中最多容纳 个条目(默认为 3),且只有当传输完成、失败或过期(超过 30 秒)后,条目才会被回收。因此,能够到达客户端 LwM2M 套接字对等方的攻击者,可以在三

CVSS 5.9 · Medium

Possible ATT&CK Techniques 1 AI

T1499.001 · OS Exhaustion Flood
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18746

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted
Source: CVE Program / CVE List V5
Vulnerability Description
parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block size with block_ctx->ctx.block_size = block_size before inspecting the return code. init_block_ctx() sets the caller's pointer to NULL and returns -ENOMEM when no entry of the static block1_contexts[] pool is free or timed out, so that store dereferences a NULL pointer. The pool holds CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries (default 3) and an entry is only reclaimed once its transfer completes, fails, or ages past 30 seconds. A peer that reaches the client's LwM2M socket can therefore start three block-wise writes on three distinct object paths with the CoAP More bit set and leave them incomplete, then send the first block of a fourth write on a new path to reach the unguarded dereference. Reachability is gated only by the connected UDP socket's source-address filter unless CONFIG_LWM2M_DTLS_SUPPORT is enabled — which has no default — so in a NoSec deployment an on-path or address-spoofing attacker needs no credentials; the same sequence is also reachable from a bootstrap or lower-trust server, and can be hit accidentally by a legitimate server running four concurrent block transfers. The write targets a fixed low address with a value between 0 and 7, so the consequence is a fatal memory fault (BusFault or corrupted low memory leading to a fault) rather than a usable memory-corruption primitive: the device crashes or resets. Confidentiality and integrity are not affected. The fix moves the store below the guard and validates the context pointer itself instead of the return code, so the context is only touched once it is known to be valid.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 3.7.0 ~ 4.5.0 -

II. Public POCs for CVE-2026-18746

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18746

请登录查看更多情报信息。

Other References for CVE-2026-18746 (2)

Same Patch Batch · zephyrproject · 2026-09-28 · 8 CVEs total

CVE-2026-16513 7.8 HIGH Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allo
CVE-2026-18413 7.8 HIGH Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer si
CVE-2026-18414 7.8 HIGH Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size
CVE-2026-18747 6.8 MEDIUM Integer underflow of net_buf length in the MCUmgr serial (SMP over console) transport lead
CVE-2026-18417 6.5 MEDIUM Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket reports an asyn
CVE-2026-18415 6.3 MEDIUM Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames
CVE-2026-18416 3.7 LOW Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_path_uri)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18746

No comments yet


Leave a comment