Junglewise Threat Intelligence

CVE-2026-10647: Zephyr RTOS deadlock in USB CDC-NCM device class

CVE-2026-10647 · Severity: medium · CVSS 5.3 · Published 2026-06-29

Technologies: Zephyr Project Zephyr RTOS. Vendors: Zephyr Project.

Executive brief

A vulnerability in the Zephyr operating system's USB networking driver can cause a device to stop communicating over its network interface. This occurs when the device tries to send data while the USB connection is in a low-power or suspended state, which is a common occurrence during host computer sleep or power management. If triggered, the device's networking capabilities will freeze, potentially affecting other system functions and requiring a full reboot to restore service.

Technical details

A deadlock vulnerability exists in the USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) due to improper error handling in the cdc_ncm_send() function. The driver ignores the return value of usbd_ep_enqueue(); if this function fails (e.g., returning -EPERM because the USB bus is suspended), the driver proceeds to call k_sem_take() with K_FOREVER. Since the completion callback required to signal the semaphore is never triggered for a failed enqueue, the shared network traffic-class TX thread deadlocks while holding the interface TX lock. This results in a permanent denial of service for the affected interface and potentially other network interfaces until a system reboot. The issue is fixed in Zephyr v4.5.0 by validating the enqueue return value and properly releasing buffers on failure.

Affected products

  • Zephyr Project Zephyr RTOS >= 4.1.0, <= 4.4.0

Timeline

  • 2026-06-23: other: Embargo date
  • 2026-06-29: advisory: GHSA-xcf7-r86m-5q9f published
  • 2026-06-29: disclosed: CVE-2026-10647 published

References

Related threats