Junglewise Threat Intelligence

CVE-2026-12365: Zephyr work queue use-after-free in timeout handling

CVE-2026-12365 · Severity: medium · CVSS 5.8 · Published 2026-08-14

Technologies: Zephyr Project Zephyr. Vendors: Zephyr Project.

Executive brief

Zephyr is an open-source real-time operating system kernel used in embedded and IoT devices. A race condition in the second-generation work queue allows kernel memory corruption or system crash when delayable work items are cancelled and freed while timeout handlers are still in flight. An attacker with influence over subsystem timing (such as connection teardown patterns) could trigger this probabilistically, leading to denial of service or potential code execution.

Technical details

The vulnerability is a use-after-free in kernel/work.c arising from insufficient synchronization between work item cancellation and timeout handler execution. When cancel_async_locked() receives a cancellation request for a delayable work item whose timeout handler (work_timeout()) is already executing, the pre-fix code fails to wait for that handler to complete. A caller can then free the work item immediately after a successful k_work_cancel_delayable_sync() call, while the handler is still pending. The handler subsequently dereferences the freed memory via z_is_timeout_handler_canceled() and performs read-modify-write operations on stale kernel pointers. This is a kernel-internal concurrency defect (no syscall entry point) triggered only on SMP systems; exploitation requires precise timing control, such as via connection churn affecting subsystem timer teardown. The fix adds spinning synchronization in unschedule_locked() and atomic ownership of K_WORK_DELAYED_BIT in work_timeout().

Affected products

  • Zephyr Project Zephyr second-generation work queue implementations

Timeline

  • 2026-08-14: disclosed

Related threats