{"id":"CVE-2026-18417","summary":"Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket reports an asynchronous error","details":"The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx-\u003euser_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_connected_cb() and zsock_close_ctx() in subsys/net/lib/sockets/sockets_inet.c), reading it back with POINTER_TO_INT(). That same field is owned by the network stack for listening TCP contexts: net_tcp_accept() stores the parent context pointer there and the TCP core passes it back to the registered accept callback. A failed accept therefore left a small integer (an errno value) where the stack expected a struct net_context .\n\nWhen the network interface carrying a listening TCP socket goes down, close_tcp_conn() in subsys/net/ip/tcp.c invokes the accept callback with -ENETDOWN and the context's user_data. In v4.3.0 the callback was not disarmed afterwards, so a second interface-down event forwarded the previously stored errno to zsock_accepted_cb(), which dereferenced it as the parent context and performed several stores through it (sock_set_error()'s read-modify-write of socket_data, k_fifo_cancel_wait(&parent-\u003erecv_q)) — the crash described in the fix's commit message. v4.3.1 and v4.4.x carry a later change clearing conn-\u003eaccept_cb after the error callback (269cb8823d3 on the v4.3 branch, 913fae5169425550f2364655298fceb79b320066 on main), which closes that repeat path; on those releases the poisoned cookie remains reachable only by a narrower race, a handshake completing alongside the interface-down still passing the stale cookie to k_fifo_put(&parent-\u003eaccept_q, ...), and by getsockopt(SO_ERROR), which reads the field back unconditionally.\n\nOn v4.3.0 an application that keeps a listening TCP socket open across repeated link-down events is sufficient to reach the defect; the triggering condition is a network-interface state change, not attacker-supplied packet data, so the practical attacker is one able to force the link down repeatedly (for example an adjacent attacker disrupting a wireless link) or one with local/physical access. Because both the faulting address and the stored data are fixed small constants derived from the errno value, the outcome is a wild-pointer access leading to a kernel fatal error — a denial of service (device crash or reset) rather than an attacker-directed memory corruption.\n\nThe fix stores the pending error in a dedicated net_context.sock_error field and converts every producer and consumer to sock_set_error()/sock_get_error(), leaving user_data untouched. As a side effect it also stops getsockopt(SO_ERROR) — which is evaluated unconditionally — from returning the kernel address held in user_data to a userspace application.","aliases":["GHSA-p8r8-8mw8-3wf9"],"modified":"2026-10-06T07:05:09.534135Z","published":"2026-09-28T23:25:23.903Z","database_specific":{"cna_assigner":"zephyr","cwe_ids":["CWE-843"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18417.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18417.json"},{"type":"ADVISORY","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p8r8-8mw8-3wf9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18417"},{"type":"FIX","url":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54"},{"type":"PACKAGE","url":"https://github.com/zephyrproject-rtos/zephyr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zephyrproject-rtos/zephyr","events":[{"introduced":"3568e1b6d5cdd51a6b964a2a1d6d29200fea2056"},{"fixed":"ef370a57d07637aaee8cec7b0bcebf4002ac8f54"}],"database_specific":{"extracted_events":[{"introduced":"4.3.0"},{"fixed":"4.4.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v4.4.0","v4.4.0-rc3","v4.4.0-rc2","v4.4.0-rc1","v4.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18417.json","vanir_signatures_modified":"2026-10-06T07:05:09Z","vanir_signatures":[{"digest":{"function_hash":"249757351194692060153143896325047353203","length":620},"id":"CVE-2026-18417-251c3f43","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_inet.c","function":"zsock_accepted_cb"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"17855606263115039085277308931834397137","length":236},"id":"CVE-2026-18417-2aade1c0","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_inet.c","function":"zsock_connected_cb"}},{"source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_inet.c","function":"zsock_connect_ctx"},"deprecated":false,"digest":{"length":1491,"function_hash":"275206462627606949070060556519625581779"},"id":"CVE-2026-18417-407325b4","signature_type":"Function","signature_version":"v1"},{"digest":{"length":7283,"function_hash":"173428397155914906857095599647928295383"},"id":"CVE-2026-18417-5041d9aa","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_inet.c","function":"zsock_getsockopt_ctx"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"336125572198177618939679228891155349146","length":1524},"id":"CVE-2026-18417-53f39ee5","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_inet.c","function":"zsock_recv_stream_timed"}},{"signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"function":"zsock_accept_ctx","file":"subsys/net/lib/sockets/sockets_inet.c"},"deprecated":false,"digest":{"function_hash":"328285279886879761799504266925994698633","length":914},"id":"CVE-2026-18417-869318cc","signature_type":"Function"},{"source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_inet.c"},"deprecated":false,"digest":{"line_hashes":["96670145089230063509703961541662844479","151973363514319119142074886778856523318","146283290681606748997627674994023846630","321230317995698414128398369873544048673","9754207811913037057534215439383653822","35613814245707601930691286850530287336","210035013191358789791254575426304321024","105403391115751245557572799662891998835","120073532724935891565493583535821176984","126742317068102497649821823808140583787","191386033358588105802450080948687508351","131927287623992668775506378994391583660","155338932707214857544045926619263852401","251647036278631537318243079811930513947","47964996117417545156109357130815827244","120250472741880214215663548902922522036","297226932718279669162723882532720096189","245571697378577249229137554426881859999","167824643550752417074122292199431356046","23145884134910986135750279514287242202","285237642213976634117665899926459772131","134402979617327092929615926571585379868","293888024150182888761506921845432426320","32869673677368490031637610454239661337","117356585375301013237150668647018461166","299956473271434463879157877716197250813","158858269766967679188559913657111469959","56603969567321320206698660312042525712","151424923543472649243754549078645506329","138869026226837696737363858625500751520","39770127941192461788126273494737622279","294463105455184646380548403744679010446","38938250988128238285796125120514274057","46457952889260312352745971307806846079","157267685603492005707157526984953280634","40146496363208111796002438181380559304","166258738287616709019706899963457612631","156823703597013903919258122699115022283","252583066329374826517772577462253949037","231044846504627601291158687254780776470"],"threshold":0.9},"id":"CVE-2026-18417-89877b19","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["282520286835445350101269198315176298469","269800403021565680910096290133993646739","83415755108879061082188902057190655799"],"threshold":0.9},"id":"CVE-2026-18417-8e258bbb","signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_internal.h"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_inet.c","function":"zsock_close_ctx"},"deprecated":false,"digest":{"function_hash":"183978121340813154249710392297435561644","length":618},"id":"CVE-2026-18417-b7d237a9"},{"deprecated":false,"digest":{"function_hash":"75193067994208300940554692176814744500","length":1073},"id":"CVE-2026-18417-bb416a75","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_inet.c","function":"zsock_received_cb"}},{"deprecated":false,"digest":{"function_hash":"193889201903867902937476103172604800125","length":417},"id":"CVE-2026-18417-cbcde105","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54","target":{"file":"subsys/net/lib/sockets/sockets_inet.c","function":"zsock_wait_data"}},{"target":{"file":"include/zephyr/net/net_context.h"},"deprecated":false,"digest":{"line_hashes":["4181058407619802964264343341766351765","101499530781924718518890346974627861783","95263714653883004058648010219398960120"],"threshold":0.9},"id":"CVE-2026-18417-efed8a99","signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}