Executive brief
Zephyr's Trusted Storage service encrypts sensitive data like cryptographic keys using industry-standard encryption. A race condition in nonce generation can cause the same encryption nonce to be used twice with the same key when two threads write to the same storage entry concurrently. Reusing nonces breaks encryption entirely: attackers with access to the storage can recover plaintext secrets and forge encrypted entries.
Technical details
The secure_storage_its_transform_aead_get_nonce() function in subsys/secure_storage/src/its/transform/aead_get.c uses unsynchronized function-local static variables to manage AEAD nonce generation and counter increments. Concurrent calls from multiple threads race on the initialization and increment paths, allowing the same nonce to be issued for different encryptions under the same key. The ITS layer applies no serialization, and both zms.c and settings/NVS back-ends retain superseded ciphertexts in flash until garbage collection, making two same-UID concurrent writes exploitable via nonce reuse against AES-GCM or ChaCha20-Poly1305.
Affected products
- Zephyr Project Zephyr RTOS versions prior to fix (exact version range not specified in advisory)
Timeline
- 2026-09-21: disclosed