Description
Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context. The functions that mutate and read it — tls_session_save(), tls_session_get(), tls_session_cache_reset(), and the settings restore handler — allocate, free, and dereference each entry's heap buffer (entry->session). Before the fix these accesses were serialized only by the per-socket context mutex ctx->lock (assigned per socket in ctx_set_lock()), which provides no mutual exclusion between different sockets touching the shared cache.

Because CONFIG_NET_SOCKETS_TLS_MAX_CLIENT_SESSION_COUNT defaults to 1, any two concurrent client sockets contend for the same slot. A thread in tls_session_get() reading entry->session inside mbedtls_ssl_session_load() can run concurrently with another thread in tls_session_save() that selects the same entry for reuse and executes mbedtls_free(entry->session) before reallocating — a use-after-free read, and a double-free when two saves evict the same entry. Both corrupt the mbedTLS heap. The cache is reached on ordinary client paths: at connect time via tls_session_store()/tls_session_restore(), and (on main) whenever a TLS 1.3 session ticket arrives during recv()/poll() via tls_session_store_current().

Exploitation requires an application that opts into per-socket client session caching (the TLS_SESSION_CACHE socket option, off by default) and runs concurrent TLS client connections on multiple threads; the timing that opens the window is influenced by the remote peer(s), so a malicious or compromised server can raise session-ticket frequency to widen it. The reliably-demonstrable impact is memory corruption leading to a crash or heap corruption (denial of service). The fix adds a dedicated session_cache_lock mutex taken across every accessor of client_cache, serializing all reads and frees and closing the race.
Published: 2026-09-14
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory corruption
Action: Patch
AI Analysis

Impact

Multiple threads can concurrently access Zephyr’s shared TLS client session cache without proper synchronization, allowing one thread to free a cache entry while another reads or reuses it. This race causes a use‑after‑free and, if two saves evict the same entry, a double‑free. The resulting misuse of the mbedTLS heap corrupts memory, leading to application crashes or other heap corruption. The vulnerability is limited to the TLS client socket context in Zephyr’s networking stack and is exercised when TLS_SESSION_CACHE is enabled.

Affected Systems

Zephyr RTOS networking subsystem (net/sockets) that implements TLS client session caching. All releases prior to the commit that introduced the session_cache_lock mutex (7f9d8ee32ba9a93fc1dbb192ca2a591ac0853bdc) are affected, especially when the default CONFIG_NET_SOCKETS_TLS_MAX_CLIENT_SESSION_COUNT remains at one.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an application that has TLS_SESSION_CACHE enabled and initiates separate TLS client connections from multiple threads; the race window is widened by a server that increases session‑ticket traffic. Because the attack depends on specific timing between concurrent threads, the likelihood of successful exploitation is low, yet a successful attack would crash the application or corrupt the heap, causing denial of service.

Generated by OpenCVE AI on September 20, 2026 at 23:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Zephyr patch that adds a dedicated session_cache_lock mutex (commit 7f9d8ee32ba9a93fc1dbb192ca2a591ac0853bdc) or upgrade to a release that contains this fix.
  • Disable the TLS_SESSION_CACHE socket option for applications that use concurrent TLS client sockets, or configure the application to use only a single TLS client per thread or process.
  • If an immediate patch is unavailable and session caching cannot be disabled, limit the number of concurrent TLS client connections or serialize the creation of TLS connections to avoid the race.
  • Ensure that CONFIG_NET_SOCKETS_TLS_MAX_CLIENT_SESSION_COUNT is set to 1 when multiple concurrent TLS client connections cannot be avoided.

Generated by OpenCVE AI on September 20, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context. The functions that mutate and read it — tls_session_save(), tls_session_get(), tls_session_cache_reset(), and the settings restore handler — allocate, free, and dereference each entry's heap buffer (entry->session). Before the fix these accesses were serialized only by the per-socket context mutex ctx->lock (assigned per socket in ctx_set_lock()), which provides no mutual exclusion between different sockets touching the shared cache. Because CONFIG_NET_SOCKETS_TLS_MAX_CLIENT_SESSION_COUNT defaults to 1, any two concurrent client sockets contend for the same slot. A thread in tls_session_get() reading entry->session inside mbedtls_ssl_session_load() can run concurrently with another thread in tls_session_save() that selects the same entry for reuse and executes mbedtls_free(entry->session) before reallocating — a use-after-free read, and a double-free when two saves evict the same entry. Both corrupt the mbedTLS heap. The cache is reached on ordinary client paths: at connect time via tls_session_store()/tls_session_restore(), and (on main) whenever a TLS 1.3 session ticket arrives during recv()/poll() via tls_session_store_current(). Exploitation requires an application that opts into per-socket client session caching (the TLS_SESSION_CACHE socket option, off by default) and runs concurrent TLS client connections on multiple threads; the timing that opens the window is influenced by the remote peer(s), so a malicious or compromised server can raise session-ticket frequency to widen it. The reliably-demonstrable impact is memory corruption leading to a crash or heap corruption (denial of service). The fix adds a dedicated session_cache_lock mutex taken across every accessor of client_cache, serializing all reads and frees and closing the race.
Title Use-after-free / double-free from unsynchronized concurrent access to the TLS client session cache in Zephyr sockets
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-14T20:04:19.577Z

Reserved: 2026-07-16T04:55:25.214Z

Link: CVE-2026-15924

cve-icon Vulnrichment

Updated: 2026-09-14T20:04:07.867Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:38.907

Modified: 2026-09-14T21:10:41.650

Link: CVE-2026-15924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses