Executive brief
A vulnerability in the Zephyr operating system's USB networking driver can cause a device to stop communicating over its network interface. This occurs when the device tries to send data while the USB connection is in a low-power or suspended state, which is a common occurrence during host computer sleep or power management. If triggered, the device's networking capabilities will freeze, potentially affecting other system functions and requiring a full reboot to restore service.
Technical details
A deadlock vulnerability exists in the USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) due to improper error handling in the cdc_ncm_send() function. The driver ignores the return value of usbd_ep_enqueue(); if this function fails (e.g., returning -EPERM because the USB bus is suspended), the driver proceeds to call k_sem_take() with K_FOREVER. Since the completion callback required to signal the semaphore is never triggered for a failed enqueue, the shared network traffic-class TX thread deadlocks while holding the interface TX lock. This results in a permanent denial of service for the affected interface and potentially other network interfaces until a system reboot. The issue is fixed in Zephyr v4.5.0 by validating the enqueue return value and properly releasing buffers on failure.
Affected products
- Zephyr Project Zephyr RTOS >= 4.1.0, <= 4.4.0
Timeline
- 2026-06-23: other: Embargo date
- 2026-06-29: advisory: GHSA-xcf7-r86m-5q9f published
- 2026-06-29: disclosed: CVE-2026-10647 published