Executive brief
A vulnerability exists in the Zephyr real-time operating system's management component (MCUmgr), which handles device management over serial or console connections. An attacker with access to the serial or console port can send a flood of data to exhaust the device's internal memory buffers, causing the system to crash. This results in a denial-of-service, rendering the device unresponsive until it is manually reset.
Technical details
A NULL pointer dereference exists in `mcumgr_serial_process_frag()` within `subsys/mgmt/mcumgr/transport/src/serial_util.c`. The function calls `net_buf_reset()` on the result of `smp_packet_alloc()` before verifying if the allocation succeeded. In production builds where assertions are disabled, `net_buf_reset()` proceeds to write to the NULL pointer when the shared MCUmgr packet pool (defaulting to 4 buffers) is exhausted. An attacker interacting with the MCUmgr serial, UART, or shell-console transports can flood the interface to trigger this exhaustion and crash the kernel. The issue was introduced in Zephyr v4.4.0 and is fixed in version 4.5.0 by reordering the NULL check before the buffer reset.
Affected products
- Zephyr Project Zephyr OS 4.4.0
Timeline
- 2026-06-26: other: Embargo date
- 2026-06-29: disclosed
- 2026-06-29: advisory