Impact
The bug involves a wild pointer dereference in Zephyr's BSD socket implementation. During asynchronous error handling, an integer error value is mistakenly stored in the user_data field of a listening TCP context, which the TCP core later reinterprets as a pointer to the parent context. If a network interface with a listening socket goes down repeatedly, this corrupted pointer is dereferenced during a second interface‑down event, causing the kernel to write through an invalid address and crash. The flaw results in a device reset and is classified as a denial‑of‑service condition, with the associated weakness identified as CWE‑843 (Type Confusion). Because the stored data are fixed errno values, the crash cannot be used to leak or alter memory beyond causing a reset, so the impact is limited to a service interruption.
Affected Systems
Affected systems are devices running Zephyr Project version 4.3.0. The problem is present only in that release; versions 4.3.1 and later include a patch that clears the accept callback after an error and redirects error storage to a dedicated sock_error field. Vendors using the Zephyr 4.3.0 kernel for embedded applications that maintain long‑lived listening TCP sockets across link changes are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score is not available, leaving the likelihood of exploitation uncertain. The vulnerability appears in the CISA KEV list as not listed, and no public exploitation has been reported. The attack vector requires an attacker to force the network interface down repeatedly, which could be achieved by disrupting a wireless link or by local or physical access. Therefore, devices that expose persistent listening sockets and rely on network reliability are at moderate risk of a device crash that could be triggered in the field or by a nearby attacker. Prompt remediation is recommended.
OpenCVE Enrichment