Junglewise Threat Intelligence

CVE-2026-10667: Zephyr RTOS use-after-free in dynamic kernel-object tracking

CVE-2026-10667 · Severity: high · CVSS 7.8 · Published 2026-07-12

Technologies: Zephyr Project Zephyr. Vendors: Zephyr Project.

Executive brief

A vulnerability exists in the Zephyr operating system's mechanism for tracking kernel objects. On systems with multiple processors, a low-privileged user can trigger a race condition that causes the system to access memory that has already been freed. This can lead to a complete system crash or allow an attacker to bypass security boundaries to gain higher privileges and access sensitive data.

Technical details

A use-after-free vulnerability exists in Zephyr's kernel/userspace.c due to inconsistent locking of the dynamic kernel object list (obj_list). While k_object_wordlist_foreach() iterates over the list using lists_lock, concurrent removals in k_object_free() and unref_check() utilize disjoint spinlocks (objfree_lock and obj_lock, respectively). On SMP systems, a node cached by the iterator's SAFE macro on one CPU can be unlinked and freed by another CPU. An unprivileged user-mode thread can trigger these paths via system calls like k_object_alloc and k_thread_abort. Successful exploitation can lead to kernel memory corruption, allowing an attacker to manipulate object permission bitmaps and escalate privileges. The fix involves serializing all obj_list modifications under the single lists_lock.

Affected products

  • Zephyr Project Zephyr RTOS 1.14.0 to 4.4.0

Timeline

  • 2019: other: Vulnerability introduced during spinlock implementation in version 1.14.0
  • 2026-07-12: disclosed: Vulnerability disclosed and advisory published
  • 2026-07-12: patched: Fixes merged into main and stable branches (v4.4, v4.3, v3.7)

References

Related threats