Executive brief
A vulnerability exists in the Zephyr real-time operating system's networking buffer library, which is used to manage data for Bluetooth, IP networking, and internal messaging. Due to a flaw in how the system tracks when a buffer is no longer in use, multiple processing threads can accidentally free the same memory simultaneously. This can lead to system crashes, memory corruption, or unpredictable behavior in devices using multi-core processors or complex networking tasks.
Technical details
The Zephyr net_buf library (lib/net_buf/buf.c) implements reference counting for both buffer headers and data blocks using non-atomic C operators. While the API is documented as self-synchronizing for cross-thread use, the lack of atomic increments/decrements allows a race condition where two threads can simultaneously observe a reference count of one and both attempt to free the resource. This results in a double-free (CWE-415) in heap-based pools or free-list corruption in fixed-data pools. The vulnerability is most prominent on SMP systems or during single-core preemption. Attackers have limited direct control over the timing, but the flaw can be triggered by standard networking or zbus message subscriber activity. The fix introduces atomic_t types and atomic operations for reference tracking.
Affected products
- Zephyr Project Zephyr RTOS >= 2.7.0, <= 4.4.0
Timeline
- 2026-04-27: other: Fix authored
- 2026-06-29: other: Embargo date
- 2026-06-30: disclosed: Advisory published and CVE assigned