CVE-2026-18746: medium-severity vulnerability in zephyrproject zephyr
NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 0.3%
exploitation probability
0.3%top 85% of all CVEs
observed exploitation
nono source reports it
parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block size with block_ctx->ctx.block_size = block_size before inspecting the return code. init_block_ctx() sets the caller's pointer to NULL and returns -ENOMEM when no entry of the static block1_contexts[] pool is free or timed out, so that store dereferences a NULL pointer.
The pool holds CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries (default 3) and an entry is only reclaimed once its transfer completes, fails, or ages past 30 seconds. A peer that reaches the client's LwM2M socket can therefore start three block-wise writes on three distinct object paths with the CoAP More bit set and leave them incomplete, then send the first block of a fourth write on a new path to reach the unguarded dereference. Reachability is gated only by the connected UDP socket's source-address filter unless CONFIG_LWM2M_DTLS_SUPPORT is enabled — which has no default — so in a NoSec deployment an on-path or address-spoofing attacker needs no credentials; the same sequence is also reachable from a bootstrap or lower-trust server, and can be hit accidentally by a legitimate server running four concurrent block transfers.
The write targets a fixed low address with a value between 0 and 7, so the consequence is a fatal memory fault (BusFault or corrupted low memory leading to a fault) rather than a usable memory-corruption primitive: the device crashes or resets. Confidentiality and integrity are not affected. The fix moves the store below the guard and validates the context pointer itself instead of the return code, so the context is only touched once it is known to be valid.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
zephyrproject · zephyrRelated CVEs — zephyrproject zephyr
In the same product, most dangerous first.
CVE-2026-8023HIGHPath traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file readEPSS 0.9%CVE-2026-10666HIGHStack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`EPSS 0.7%CVE-2026-10665HIGHHeap buffer overflow on WireGuard receive path via unbounded incoming packet lengthEPSS 0.6%CVE-2026-10672HIGHUnterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)EPSS 0.6%CVE-2026-10686MEDIUMMissing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routersEPSS 0.5%CVE-2026-13214CRITICALStack buffer overflow in OCPP GetConfiguration key parsingEPSS 0.5%