Junglewise Threat Intelligence

CVE-2026-10639: Zephyr OS use-after-free in ICMPv4 echo request handler

CVE-2026-10639 · Severity: medium · CVSS 4.8 · Published 2026-06-16

Technologies: Zephyr Project Zephyr OS. Vendors: Zephyr Project.

Executive brief

Zephyr is an open-source operating system designed for resource-constrained IoT devices. A flaw in its networking component allows a remote attacker to potentially crash a device or corrupt its internal network statistics by sending a standard ping request. This occurs because the system attempts to update its internal counters using information from a data packet that has already been processed and deleted from memory.

Technical details

A use-after-free (UAF) vulnerability exists in `subsys/net/ip/icmpv4.c` within the `icmpv4_handle_echo_request()` function. The code hands off an echo-reply packet to the transmission path via `net_try_send_data()`, which transfers ownership and may result in the packet being freed immediately. However, the code subsequently attempts to access the packet's interface pointer to update ICMP statistics. If `CONFIG_NET_STATISTICS_PER_INTERFACE` is enabled, this results in a write-through of a stale or recycled pointer. An unauthenticated remote attacker can trigger this path by sending an ICMPv4 echo request (ping). The vulnerability is subject to a race condition and is fixed in version 4.5.0 by caching the interface pointer before transmission.

Affected products

  • Zephyr Project Zephyr OS 1.14.0 to 4.4.0

Timeline

  • 2019-02-01: other: Vulnerability introduced in version 1.14.0-rc1
  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched: Fixed in version 4.5.0 and backported to LTS branches

References

Related threats