Impact
Multiple threads can concurrently access Zephyr’s shared TLS client session cache without proper synchronization, allowing one thread to free a cache entry while another reads or reuses it. This race causes a use‑after‑free and, if two saves evict the same entry, a double‑free. The resulting misuse of the mbedTLS heap corrupts memory, leading to application crashes or other heap corruption. The vulnerability is limited to the TLS client socket context in Zephyr’s networking stack and is exercised when TLS_SESSION_CACHE is enabled.
Affected Systems
Zephyr RTOS networking subsystem (net/sockets) that implements TLS client session caching. All releases prior to the commit that introduced the session_cache_lock mutex (7f9d8ee32ba9a93fc1dbb192ca2a591ac0853bdc) are affected, especially when the default CONFIG_NET_SOCKETS_TLS_MAX_CLIENT_SESSION_COUNT remains at one.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an application that has TLS_SESSION_CACHE enabled and initiates separate TLS client connections from multiple threads; the race window is widened by a server that increases session‑ticket traffic. Because the attack depends on specific timing between concurrent threads, the likelihood of successful exploitation is low, yet a successful attack would crash the application or corrupt the heap, causing denial of service.
OpenCVE Enrichment