Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18747— Integer underflow of net_buf length in the MCUmgr serial (SMP over console) transport leads to out-of-bounds read

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

这段代码涉及一个针对 MCUmgr SMP-over-console 传输机制的安全漏洞。以下是对该漏洞描述的中文翻译: MCUmgr SMP-over-console 传输机制在 函数中(位于 )解码 base64 帧,从中读取一个 16 位的包长度,验证 CRC 校验和,然后无条件地剥离末尾的 CRC 校验和,执行的操作为 。 函数接受任何声明的长度值,包括 0 和 1。由于 在零字节上运算时返回零种子值,因此声明长度为 0 的包可以免费通过校验和测试。 由于 是一个 类型,上述减法操作会导致下溢(underf

CVSS 6.8 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18747

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Integer underflow of net_buf length in the MCUmgr serial (SMP over console) transport leads to out-of-bounds read
Source: CVE Program / CVE List V5
Vulnerability Description
The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len -= 2U; in mcumgr_serial_process_frag() (subsys/mgmt/mcumgr/transport/src/serial_util.c). mcumgr_serial_extract_len() accepted any declared length, including 0 and 1, and a packet declaring length 0 passes the checksum test for free because crc16_itu_t() over zero bytes returns the zero seed. Since net_buf::len is a uint16_t, the subtraction underflows and the buffer is handed to SMP claiming roughly 65 KB of payload while its data area is only CONFIG_MCUMGR_TRANSPORT_NETBUF_SIZE bytes (default 384). The trigger is a single unauthenticated 7-byte line on the management console — the 0x06 0x09 packet marker followed by the base64 group AAA= and a newline — delivered to any transport built on this helper: CONFIG_MCUMGR_TRANSPORT_UART (smp_uart.c) or CONFIG_MCUMGR_TRANSPORT_SHELL (smp_shell.c), both of which select MCUMGR_TRANSPORT_SERIAL_HAS_SMP_OVER_CONSOLE. No prior session state, fragmentation or credentials are required to trigger the underflow, and the malformed frame is mishandled before any command handler or command-level access control runs. The attacker only needs write access to that console, which on many boards is a USB CDC-ACM port rather than a bare UART header. With the inflated length, smp_process_request_packet() in subsys/mgmt/mcumgr/smp/src/smp.c loses its bound: cbor_nb_reader_init() gives the CBOR decoder a ~65 KB window into a 384-byte buffer, and each request header's nh_len is checked only against the inflated length. On its own the 7-byte frame re-parses whatever stale bytes the reused pool buffer still holds, typically a replay of the previously received request followed by a parse error, without leaving the buffer. Because the transport is unauthenticated, though, the attacker also controls the frames sent before the trigger, and can stage buffer contents so that a request succeeds with an nh_len larger than the buffer; net_buf_pull(), guarded only by __ASSERT_NO_MSG, then moves the parse cursor out of bounds and the loop reads further headers and CBOR from adjacent memory. The consequence is an out-of-bounds read that can fault the MCUmgr thread (denial of service); memory disclosure is also possible, since the default-enabled os echo handler (CONFIG_MCUMGR_GRP_OS_ECHO) decodes its string inside that window and copies it into its response. There is no integrity gain beyond what the unauthenticated transport already permits. The fix rejects any declared packet length of two bytes or fewer in mcumgr_serial_extract_len(), so the CRC-strip subtraction can no longer underflow. The identical pattern remains in the test-only loopback transport subsys/mgmt/mcumgr/transport/src/smp_dummy.c (CONFIG_MCUMGR_TRANSPORT_DUMMY), which has no external input path and therefore carries no practical exposure.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 1.11.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-18747

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18747

请登录查看更多情报信息。

Other References for CVE-2026-18747 (2)

Same Patch Batch · zephyrproject · 2026-09-28 · 8 CVEs total

CVE-2026-16513 7.8 HIGH Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allo
CVE-2026-18413 7.8 HIGH Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer si
CVE-2026-18414 7.8 HIGH Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size
CVE-2026-18417 6.5 MEDIUM Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket reports an asyn
CVE-2026-18415 6.3 MEDIUM Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames
CVE-2026-18746 5.9 MEDIUM NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhau
CVE-2026-18416 3.7 LOW Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_path_uri)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18747

No comments yet


Leave a comment