Junglewise Threat Intelligence

CVE-2026-10671: Zephyr RTOS kernel wait queue corruption in pipe initialization

CVE-2026-10671 · Severity: high · CVSS 7.1 · Published 2026-07-14

Technologies: Zephyr Project Zephyr RTOS. Vendors: Zephyr Project.

Executive brief

Zephyr is an open-source operating system designed for resource-constrained IoT devices. A flaw in how the system handles communication 'pipes' allows a restricted user-level program to reset a pipe while other parts of the system are still using it. This can lead to system instability, data loss, or a complete device crash, potentially allowing a malicious application to bypass security boundaries and corrupt the core operating system memory.

Technical details

A vulnerability exists in the Zephyr kernel's syscall verifier for pipe initialization (`z_vrfy_k_pipe_init`). The verifier incorrectly used the `K_SYSCALL_OBJ()` macro, which permits the re-initialization of already-initialized kernel objects, instead of `K_SYSCALL_OBJ_NEVER_INIT()`. On builds with `CONFIG_USERSPACE` enabled, an unprivileged thread with access to a `k_pipe` object can invoke `k_pipe_init` on a live pipe. This causes the kernel to reset wait queues without accounting for blocked threads, leaving them 'orphaned' with stale pointers. When these orphaned threads are later processed by the scheduler, the system performs a `sys_dlist_remove()` using dangling pointers, resulting in an attacker-controlled invalid kernel write and list corruption. The issue is fixed in version 4.5.0 and backported to 4.4, 4.3, and 3.7 branches.

Affected products

  • Zephyr Project Zephyr RTOS 4.1.0 to 4.4.0

Timeline

  • 2026-07-14: advisory: GHSA-p8w8-3x99-mg8f published
  • 2026-07-14: disclosed
  • 2026-07-14: patched

References

Related threats