Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-10653

Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-415 Doble liberación
Fecha de publicación:
30/06/2026
Última modificación:
06/08/2026

Descripción

*** Pendiente de traducción *** The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf-&gt;ref and the per-data-block ref_count at the start of each variable/heap data allocation -- with plain non-atomic C operators (buf-&gt;ref++, if (--buf-&gt;ref &gt; 0), if (--(*ref_count))).<br /> <br /> The API is documented as self-synchronizing: callers may share one buffer across threads (e.g. via k_fifo) and each holder independently calls net_buf_unref() with no surrounding lock. Under true concurrency (SMP, or single-core preemption between the non-atomic load and store while another context unrefs the same buffer), two holders can both observe the same prior reference value and both conclude they are the last reference.<br /> <br /> For heap/variable-data pools (mem_pool_data_unref/heap_data_unref, used by zbus message subscribers, the IP stack RX/TX buffers when CONFIG_NET_BUF_FIXED_DATA_SIZE=n, capture, wireguard, ISO-TP and usbip) this produces a double k_heap_free()/k_free() of the same block -- heap-metadata corruption and a use-after-free on the heap-hardening poison pattern.<br /> <br /> For the per-header refcount the buffer is returned to the pool free LIFO twice for any pool type (including fixed-data pools used by Bluetooth and networking), corrupting the free list so a later allocation hands the same buffer to two owners.<br /> <br /> The fix converts both refcounts to atomic_inc/atomic_dec (overlaying buf-&gt;ref in an atomic_t-sized union and changing the data-block refcount from uint8_t to atomic_t).<br /> <br /> Impact is gated on genuine concurrency and on an application architecture that shares one buffer among multiple independent unref&amp;#39;ers; the trigger is a refcount/timing race rather than packet content, so an external attacker has at most weak indirect influence over the race window. Affects all Zephyr releases through v4.4.0.<br /> <br /> This fix is not being backported to v3.7-branch (LTS). The backport was attempted and closed unmerged (#111181): the v3.7 networking tree has diverged from main, and the new atomic word-packing -- together with the assertions it adds -- turns pre-existing v3.7-only reference-counting defects elsewhere in the stack into hard faults, so landing the change faithfully would mean pulling an open-ended set of additional v3.7-only fixes into an LTS branch. v3.7 remains affected. Applications on v3.7 that share one net_buf across threads should serialize their own net_buf_unref() calls rather than rely on the documented self-synchronizing behaviour. The fix is on main and has been backported to v4.3-branch (#110852) and v4.4-branch (#110853).

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:* 2.7.0 (incluyendo) 4.4.1 (incluyendo)