Executive brief
Zephyr is an operating system designed for resource-constrained Internet of Things (IoT) devices. A flaw in how it handles network address lookups (DNS) allows a remote attacker to corrupt the device's memory. This can lead to device crashes, unpredictable behavior, or a complete denial of service, potentially disrupting operations or requiring manual resets of deployed hardware.
Technical details
A use-after-return vulnerability exists in 'subsys/net/lib/sockets/getaddrinfo.c' within the Zephyr RTOS. The 'getaddrinfo' function passes a pointer to a stack-allocated state object as 'user_data' for asynchronous DNS queries. If the socket layer's semaphore wait times out before the resolver completes, the code retries the query without cancelling the previous request. This leaves a stale pointer to an out-of-scope stack frame in the resolver's callback registry. An attacker can trigger a write to this stale pointer by sending a spoofed UDP DNS response with a matching 16-bit transaction ID, or the corruption may occur naturally via delayed query-timeout work. This leads to stack memory corruption, resulting in crashes or potential remote code execution. The issue is fixed in version 4.5.0 by ensuring timed-out queries are cancelled before retrying.
Affected products
- Zephyr Project Zephyr 4.0.0 to 4.4.0
Timeline
- 2024-03-06: other: Vulnerability introduced in commit 5be8413
- 2026-06-22: other: Embargo date
- 2026-06-28: disclosed: Advisory published and CVE assigned
- 2026-06-28: patched: Fix merged into main branch