Junglewise Threat Intelligence

CVE-2026-10653: Zephyr RTOS double free in net_buf library reference counting

CVE-2026-10653 · Severity: medium · CVSS 6.4 · Published 2026-06-30

Technologies: Zephyr Project Zephyr RTOS. Vendors: Zephyr Project.

Executive brief

A vulnerability exists in the Zephyr real-time operating system's networking buffer library, which is used to manage data for Bluetooth, IP networking, and internal messaging. Due to a flaw in how the system tracks when a buffer is no longer in use, multiple processing threads can accidentally free the same memory simultaneously. This can lead to system crashes, memory corruption, or unpredictable behavior in devices using multi-core processors or complex networking tasks.

Technical details

The Zephyr net_buf library (lib/net_buf/buf.c) implements reference counting for both buffer headers and data blocks using non-atomic C operators. While the API is documented as self-synchronizing for cross-thread use, the lack of atomic increments/decrements allows a race condition where two threads can simultaneously observe a reference count of one and both attempt to free the resource. This results in a double-free (CWE-415) in heap-based pools or free-list corruption in fixed-data pools. The vulnerability is most prominent on SMP systems or during single-core preemption. Attackers have limited direct control over the timing, but the flaw can be triggered by standard networking or zbus message subscriber activity. The fix introduces atomic_t types and atomic operations for reference tracking.

Affected products

  • Zephyr Project Zephyr RTOS >= 2.7.0, <= 4.4.0

Timeline

  • 2026-04-27: other: Fix authored
  • 2026-06-29: other: Embargo date
  • 2026-06-30: disclosed: Advisory published and CVE assigned

References

Related threats