目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-18747— MCUmgr 串口传输整数下溢出导致越界读取漏洞

一分钟漏洞结论

影响对象
zephyrproject zephyr
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

这段代码涉及一个针对 MCUmgr SMP-over-console 传输机制的安全漏洞。以下是对该漏洞描述的中文翻译: MCUmgr SMP-over-console 传输机制在 函数中(位于 )解码 base64 帧,从中读取一个 16 位的包长度,验证 CRC 校验和,然后无条件地剥离末尾的 CRC 校验和,执行的操作为 。 函数接受任何声明的长度值,包括 0 和 1。由于 在零字节上运算时返回零种子值,因此声明长度为 0 的包可以免费通过校验和测试。 由于 是一个 类型,上述减法操作会导致下溢(underf

CVSS 6.8 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-18747 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Integer underflow of net_buf length in the MCUmgr serial (SMP over console) transport leads to out-of-bounds read
来源: CVE Program / CVE List V5
Vulnerability Description
The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/mcumgr/transport/src/serial_util.c). mcumgr_serial_extract_len() accepted any declared length, including 0 and 1, and a packet declaring length 0 passes the checksum test for free because crc16_itu_t() over zero bytes returns the zero seed. Since net_buf::len is a uint16_t, the subtraction underflows and the buffer is handed to SMP claiming roughly 65 KB of payload while its data area is only CONFIG_MCUMGR_TRANSPORT_NETBUF_SIZE bytes (default 384). The trigger is a single unauthenticated 7-byte line on the management console — the 0x06 0x09 packet marker followed by the base64 group AAA= and a newline — delivered to any transport built on this helper: CONFIG_MCUMGR_TRANSPORT_UART (smp_uart.c) or CONFIG_MCUMGR_TRANSPORT_SHELL (smp_shell.c), both of which select MCUMGR_TRANSPORT_SERIAL_HAS_SMP_OVER_CONSOLE. No prior session state, fragmentation or credentials are required to trigger the underflow, and the malformed frame is mishandled before any command handler or command-level access control runs. The attacker only needs write access to that console, which on many boards is a USB CDC-ACM port rather than a bare UART header. With the inflated length, smp_process_request_packet() in subsys/mgmt/mcumgr/smp/src/smp.c loses its bound: cbor_nb_reader_init() gives the CBOR decoder a ~65 KB window into a 384-byte buffer, and each request header's nh_len is checked only against the inflated length. On its own the 7-byte frame re-parses whatever stale bytes the reused pool buffer still holds, typically a replay of the previously received request followed by a parse error, without leaving the buffer. Because the transport is unauthenticated, though, the attacker also controls the frames sent before the trigger, and can stage buffer contents so that a request succeeds with an nh_len larger than the buffer; net_buf_pull(), guarded only by __ASSERT_NO_MSG, then moves the parse cursor out of bounds and the loop reads further headers and CBOR from adjacent memory. The consequence is an out-of-bounds read that can fault the MCUmgr thread (denial of service); memory disclosure is also possible, since the default-enabled os echo handler (CONFIG_MCUMGR_GRP_OS_ECHO) decodes its string inside that window and copies it into its response. There is no integrity gain beyond what the unauthenticated transport already permits. The fix rejects any declared packet length of two bytes or fewer in mcumgr_serial_extract_len(), so the CRC-strip subtraction can no longer underflow. The identical pattern remains in the test-only loopback transport subsys/mgmt/mcumgr/transport/src/smp_dummy.c (CONFIG_MCUMGR_TRANSPORT_DUMMY), which has no external input path and therefore carries no practical exposure.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
zephyrproject zephyr 1.11.0 ~ 4.4.2 -

二、漏洞 CVE-2026-18747 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-18747 的情报信息

请登录查看更多情报信息。

CVE-2026-18747 其他参考 (2)

同批安全公告 · zephyrproject · 2026-09-28 · 共 8 条

CVE-2026-16513 7.8 HIGH RTIO系统调用验证器漏洞允许任意内核写入
CVE-2026-18413 7.8 HIGH NXP MCUX LPADC ADC驱动越界写入漏洞
CVE-2026-18414 7.8 HIGH ADI MAX32 ADC驱动越界写入漏洞
CVE-2026-18417 6.5 MEDIUM Zephyr BSD套接字TCP监听异步错误野指针解引用漏洞
CVE-2026-18415 6.3 MEDIUM IEEE 802.15.4 L2发送路径越界写入漏洞
CVE-2026-18746 5.9 MEDIUM Zephyr LwM2M客户端空指针解引用漏洞
CVE-2026-18416 3.7 LOW CoAP well-known-core 边界读取漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-18747

暂无评论


发表评论