Impact
The bug is a heap memory leak in Zephyr's mcumgr settings‑management handlers (settings_mgmt_read, settings_mgmt_write, and settings_mgmt_delete). When the access‑hook feature is enabled and the application hook rejects a request by returning MGMT_CB_ERROR_RC, the handler returns before reaching the free label, leaking the heap buffer that was allocated for the request. The leaked memory persists until a reboot, so repeated rejected requests will eventually exhaust the kernel heap, causing mcumgr to fail and potentially disrupting other services that rely on heap allocation. The flaw impacts availability only; it does not corrupt memory or expose data.
Affected Systems
Zephyr Project Zephyr. The vulnerability affects configurations that enable CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP, enable the access hook, and register a hook that returns MGMT_CB_ERROR_RC. Devices using the default stack buffer type are not affected.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. EPSS score of 0.00275 indicates a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. The flaw can be triggered over unauthenticated SMP transports such as Bluetooth LE, UART, or UDP, so an attacker only needs to send arbitrarily many read, write, or delete commands that the access hook rejects. The resulting heap exhaustion can lead to denial of service of mcumgr and other heap consumers. Because no authentication is required, the attack is feasible on any exposed device that meets the configuration conditions, but the lack of data disclosure or code execution limits the risk to availability.
OpenCVE Enrichment