Description
The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_malloc() when CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP is enabled, relying on the end: label to k_free() them. When CONFIG_MCUMGR_GRP_SETTINGS_ACCESS_HOOK is also enabled and the application access hook rejects a request by returning status MGMT_CB_ERROR_RC, the handler executed return ret_rc; directly, bypassing end: and leaking the heap allocation on every rejected request.

The settings handlers are reachable over the unauthenticated SMP transport (Bluetooth LE, UART, or UDP, depending on product configuration). The access hook is the mechanism applications use to deny unauthorized settings access, and MGMT_CB_ERROR_RC is a common rejection style, so an attacker who can send settings read/write/delete commands that the hook rejects triggers a heap leak on each attempt.

Because the leaked memory is never reclaimed until reboot, a sustained stream of rejected requests monotonically exhausts the kernel heap until k_malloc() fails, denying mcumgr service and impacting any other heap consumer on the device — a denial of service. The impact is availability-only; there is no memory corruption or information disclosure. Only configurations that select the heap buffer type, enable the access hook, and register a hook that returns MGMT_CB_ERROR_RC are affected (the default stack buffer type cannot leak).
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

The bug is a heap memory leak in Zephyr's mcumgr settings‑management handlers (settings_mgmt_read, settings_mgmt_write, and settings_mgmt_delete). When the access‑hook feature is enabled and the application hook rejects a request by returning MGMT_CB_ERROR_RC, the handler returns before reaching the free label, leaking the heap buffer that was allocated for the request. The leaked memory persists until a reboot, so repeated rejected requests will eventually exhaust the kernel heap, causing mcumgr to fail and potentially disrupting other services that rely on heap allocation. The flaw impacts availability only; it does not corrupt memory or expose data.

Affected Systems

Zephyr Project Zephyr. The vulnerability affects configurations that enable CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP, enable the access hook, and register a hook that returns MGMT_CB_ERROR_RC. Devices using the default stack buffer type are not affected.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. EPSS score of 0.00275 indicates a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. The flaw can be triggered over unauthenticated SMP transports such as Bluetooth LE, UART, or UDP, so an attacker only needs to send arbitrarily many read, write, or delete commands that the access hook rejects. The resulting heap exhaustion can lead to denial of service of mcumgr and other heap consumers. Because no authentication is required, the attack is feasible on any exposed device that meets the configuration conditions, but the lack of data disclosure or code execution limits the risk to availability.

Generated by OpenCVE AI on September 15, 2026 at 16:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zephyr to a release that includes commit fabc488d5b44143e5bd70dd373182c4395a816b9 or newer.
  • If a patch cannot be applied immediately, reconfigure the device to use the default stack buffer type by disabling CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP.
  • Alternatively, disable CONFIG_MCUMGR_GRP_SETTINGS_ACCESS_HOOK or modify the access hook so that it does not return MGMT_CB_ERROR_RC when rejecting requests.

Generated by OpenCVE AI on September 15, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Sun, 13 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_malloc() when CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP is enabled, relying on the end: label to k_free() them. When CONFIG_MCUMGR_GRP_SETTINGS_ACCESS_HOOK is also enabled and the application access hook rejects a request by returning status MGMT_CB_ERROR_RC, the handler executed return ret_rc; directly, bypassing end: and leaking the heap allocation on every rejected request. The settings handlers are reachable over the unauthenticated SMP transport (Bluetooth LE, UART, or UDP, depending on product configuration). The access hook is the mechanism applications use to deny unauthorized settings access, and MGMT_CB_ERROR_RC is a common rejection style, so an attacker who can send settings read/write/delete commands that the hook rejects triggers a heap leak on each attempt. Because the leaked memory is never reclaimed until reboot, a sustained stream of rejected requests monotonically exhausts the kernel heap until k_malloc() fails, denying mcumgr service and impacting any other heap consumer on the device — a denial of service. The impact is availability-only; there is no memory corruption or information disclosure. Only configurations that select the heap buffer type, enable the access hook, and register a hook that returns MGMT_CB_ERROR_RC are affected (the default stack buffer type cannot leak).
Title Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to denial of service
Weaknesses CWE-401
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-14T11:19:51.194Z

Reserved: 2026-07-15T17:38:08.763Z

Link: CVE-2026-15892

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:55.476Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T23:16:28.023

Modified: 2026-09-14T21:10:41.650

Link: CVE-2026-15892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime