Junglewise Threat Intelligence

CVE-2026-10665: Zephyr RTOS out-of-bounds write in WireGuard wg_process_data_message

CVE-2026-10665 · Severity: high · CVSS 7.4 · Published 2026-07-12

Technologies: Zephyr Project Zephyr RTOS. Vendors: Zephyr Project.

Executive brief

Zephyr RTOS, a popular operating system for embedded and IoT devices, contains a security flaw in its WireGuard VPN implementation. An attacker who can send network traffic to a device using this VPN can cause the system to crash or potentially execute unauthorized commands by sending specially crafted, oversized data packets. This could lead to a complete service outage or compromise the integrity of the device's operations.

Technical details

An out-of-bounds write (CWE-787) exists in the Zephyr WireGuard subsystem within `subsys/net/lib/wireguard/wg_crypto.c`. The function `wg_process_data_message()` fails to validate the length of incoming transport-data payloads against the fixed pool buffer size `CONFIG_WIREGUARD_BUF_LEN`. By passing an attacker-controlled `data_len` to `net_buf_linearize()` as both the destination capacity and copy length, the internal bounds checking is bypassed. This allows a malicious peer or an on-path attacker with a valid receiver session index to trigger a heap-based buffer overflow before the Poly1305 authentication check occurs. The vulnerability was introduced in Zephyr 4.4.0 and is addressed by adding explicit length checks and correcting the linearization capacity argument.

Affected products

  • Zephyr Project Zephyr RTOS 4.4.0

Timeline

  • 2026-07-12: advisory: GHSA-3wqm-wgx2-9367 published
  • 2026-07-12: disclosed: CVE-2026-10665 published
  • 2026-07-12: patched: Fix merged into main and v4.4-branch

References

Related threats