Junglewise Threat Intelligence

CVE-2026-11811: Zephyr RTOS UpdateHub socket descriptor leak in CoAP/DTLS setup

CVE-2026-11811 · Severity: low · CVSS 3.7 · Published 2026-08-10

Technologies: Zephyr Project Zephyr RTOS. Vendors: Zephyr Project.

Executive brief

The UpdateHub over-the-air update client in Zephyr RTOS leaks network socket descriptors each time it fails to connect to the update server. As these failures accumulate—triggered by network issues or periodic reconnection attempts—the device gradually exhausts its socket pool, eventually causing network-wide degradation until rebooted. While each failure is automatic and the leak is slow, devices running this component may become unreachable or non-functional without manual intervention.

Technical details

The vulnerability is a resource leak in the start_coap_client() function within subsys/mgmt/updatehub/updatehub.c. The root cause is a logic error in error handling: a ret flag initialized to -1 gates cleanup code, but when zsock_setsockopt() or zsock_connect() fails, the gate condition (ret > 0) is never true, so cleanup_connection() is skipped. Each failed connection attempt permanently leaks one CoAP/DTLS socket descriptor from the global ctx.sock, as subsequent attempts overwrite it without closing the previous one. The vulnerability is reachable over the network whenever the device cannot establish a connection to the UpdateHub server—either due to natural network unavailability, server downtime, or attacker-induced packet loss. Once the shared socket pool is exhausted, device-wide networking degradation occurs until reboot.

Affected products

  • Zephyr Project Zephyr RTOS builds with UpdateHub client enabled

Timeline

  • 2026-08-10: disclosed
  • 2026-08-10: advisory

Related threats