CVE-2026-18746
Last modified
CVE-2026-18746 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block size with block_ctx->ctx.block_size = block_size before inspecting the return code.
Description
parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block size with block_ctx->ctx.block_size = block_size before inspecting the return code. init_block_ctx() sets the caller's pointer to NULL and returns -ENOMEM when no entry of the static block1_contexts[] pool is free or timed out, so that store dereferences a NULL pointer. The pool holds CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries (default 3) and an entry is only reclaimed once its transfer completes, fails, or ages past 30 seconds. A peer that reaches the client's LwM2M socket can therefore start three block-wise writes on three distinct object paths with the CoAP More bit set and leave them incomplete, then send the first block of a fourth write on a new path to reach the unguarded dereference. Reachability is gated only by the connected UDP socket's source-address filter unless CONFIG_LWM2M_DTLS_SUPPORT is enabled — which has no default — so in a NoSec deployment an on-path or address-spoofing attacker needs no credentials; the same sequence is also reachable from a bootstrap or lower-trust server, and can be hit accidentally by a legitimate server running four concurrent block transfers. The write targets a fixed low address with a value between 0 and 7, so the consequence is a fatal memory fault (BusFault or corrupted low memory leading to a fault) rather than a usable memory-corruption primitive: the device crashes or resets. Confidentiality and integrity are not affected. The fix moves the store below the guard and validates the context pointer itself instead of the return code, so the context is only touched once it is known to be valid.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| zephyrproject | zephyr | >= 3.7.0, < 4.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-18746?
How severe is CVE-2026-18746?
How do I fix CVE-2026-18746?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18739A flaw was found in popt, a command-line option parsing libr…2.5
- CVE-2026-1874Always-Incorrect Control Flow Implementation vulnerability i…7.5
- CVE-2026-18741Worksuite SaaS versions prior to 6.0.14 contains a stored cr…4.8
- CVE-2026-18743A flaw was found in popt. This vulnerability allows an attac…2.5
- CVE-2026-18744Any authenticated case participant can fetch any OTHER vendo…6.5
- CVE-2026-18745Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-18747The MCUmgr SMP-over-console transport decodes a base64 frame…6.8
- CVE-2026-18749The type=track branch authorises on _is_my_case(t_attach.cas…9.8
- CVE-2026-1875Improper Resource Shutdown or Release vulnerability in Mitsu…7.5
- CVE-2026-18750vinny/views.py: (ModifyEmailNotifications) IDOR: view fetche…5.3
- CVE-2026-18751External control of file name or path vulnerability in Citri…5.2
- CVE-2026-18752The Persistent Login plugin for WordPress is vulnerable to g…6.5
Are you affected by CVE-2026-18746?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
