{"id":"CVE-2026-10684","summary":"Out-of-bounds read in coredump shell when printing stored-dump target code","details":"In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredump header directly as an index into coredump_target_code2str[], a fixed 7-element array of string pointers, with no bounds check.\n\nA stored coredump whose tgt_code is \u003e= 7 causes an out-of-bounds read of a char* up to ~64K entries past the array; that value is passed as the %s argument to shell_print, which dereferences and walks it as a string. The result is either disclosure of device memory contents to the shell user or a crash when the out-of-bounds pointer is unmapped.\n\nThe defect is reached via the coredump print shell command (cmd_coredump_print_stored_dump -\u003e pretty_print_coredump -\u003e parse_and_print_coredump -\u003e print_coredump_hdr). The tgt_code field is device-generated and in-range during normal crash handling, so triggering requires local shell access plus the ability to stage or corrupt the stored coredump in the flash/in-memory backend.\n\nIntroduced in v4.2.0 (commit 13abd7fe730) and present through v4.4.0; fixed by clamping out-of-range codes to the 'unknown' (index 0) entry.","aliases":["GHSA-9fw2-4429-49q8"],"modified":"2026-07-31T03:49:10.955165039Z","published":"2026-07-29T18:03:08.771Z","database_specific":{"cna_assigner":"zephyr","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10684.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10684.json"},{"type":"ADVISORY","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-9fw2-4429-49q8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10684"},{"type":"FIX","url":"https://github.com/zephyrproject-rtos/zephyr/commit/a9226324e8bd1f8adecafb1b6e0603f781dc750c"},{"type":"PACKAGE","url":"https://github.com/zephyrproject-rtos/zephyr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zephyrproject-rtos/zephyr","events":[{"introduced":"413b789deb391d3a37d06b463288a5fe765ee57e"},{"fixed":"75f67d766726351b30199f9a2bf55803d717a3be"},{"introduced":"684c9e8f32e4373a21098559f748f06915f950c9"},{"last_affected":"1f6485eca25431b5ff27ce9a754218c9e559bbbb"}],"database_specific":{"extracted_events":[{"introduced":"4.2.0"},{"fixed":"4.3.1"},{"introduced":"4.4.0"},{"last_affected":"4.4.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v4.3.1-rc1","v4.4.1","v4.4.1-rc1","v4.4.0","v4.3.0","v4.3.0-rc3","v4.3.0-rc2","v4.3.0-rc1","v4.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10684.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L"}]}