CVE-2026-10648

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
29/06/2026
Last modified:
14/07/2026

Description

mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of smp_packet_alloc() before checking it for NULL. smp_packet_alloc() uses net_buf_alloc(K_NO_WAIT) against the shared MCUmgr packet pool (CONFIG_MCUMGR_TRANSPORT_NETBUF_COUNT, default 4), which returns NULL when the pool is exhausted. In default builds the __ASSERT_NO_MSG in net_buf_reset is a no-op, so net_buf_simple_reset writes through the NULL pointer (buf-&gt;len = 0; buf-&gt;data = buf-&gt;__buf), causing a fault/crash.<br /> <br /> The fragment data reaches this code from attacker-controlled bytes on the MCUmgr serial/UART/shell-console transports (smp_uart.c, smp_raw_uart.c, smp_shell.c), and a fresh buffer is allocated at the start of essentially every new packet. An attacker on the serial/console link can flood the transport to drive the 4-entry buffer pool to exhaustion and induce the NULL dereference, crashing the device (denial of service).<br /> <br /> The defect was introduced after the original MCUmgr rework and shipped in Zephyr v4.4.0. The fix moves the NULL check ahead of net_buf_reset.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zephyrproject:zephyr:4.4.0:-:*:*:*:*:*:*
cpe:2.3:o:zephyrproject:zephyr:4.4.0:rc1:*:*:*:*:*:*
cpe:2.3:o:zephyrproject:zephyr:4.4.0:rc2:*:*:*:*:*:*
cpe:2.3:o:zephyrproject:zephyr:4.4.0:rc3:*:*:*:*:*:*