Executive brief
Zephyr's USB Device Firmware Update (DFU) implementation contains a crash flaw in the experimental device_next stack. An attacker controlling a USB host can send a specially crafted zero-length firmware download request that causes the device to crash or reset, disrupting operations. The impact is limited to availability; no data is exposed or corrupted.
Technical details
The vulnerability is a NULL pointer dereference (CWE-476) in handle_download() within subsys/usb/device_next/class/usbd_dfu.c. When a DFU_DNLOAD request arrives with no Data OUT stage (specifically, the zero-length terminating download used in the DFU protocol), the USB core passes a NULL buffer pointer to the handler. The handler fails to check if buf is non-NULL before computing MIN(setup->wLength, buf->len) and passing buf->data to the image write callback, causing a NULL+offset read and fatal CPU fault. Attack requires the device to have DFU download support enabled with a registered image, and the attacker must control the USB host. A patch adds an explicit NULL check before dereferencing buf.
Affected products
- Zephyr Project Zephyr device_next experimental USB stack (affected versions not explicitly specified)
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Fix committed in commit 552ca371257597b71490482d5cc597157ea60f12 adding NULL check before buf dereference