Description
parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block size with block_ctx->ctx.block_size = block_size before inspecting the return code. init_block_ctx() sets the caller's pointer to NULL and returns -ENOMEM when no entry of the static block1_contexts[] pool is free or timed out, so that store dereferences a NULL pointer.

The pool holds CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries (default 3) and an entry is only reclaimed once its transfer completes, fails, or ages past 30 seconds. A peer that reaches the client's LwM2M socket can therefore start three block-wise writes on three distinct object paths with the CoAP More bit set and leave them incomplete, then send the first block of a fourth write on a new path to reach the unguarded dereference. Reachability is gated only by the connected UDP socket's source-address filter unless CONFIG_LWM2M_DTLS_SUPPORT is enabled — which has no default — so in a NoSec deployment an on-path or address-spoofing attacker needs no credentials; the same sequence is also reachable from a bootstrap or lower-trust server, and can be hit accidentally by a legitimate server running four concurrent block transfers.

The write targets a fixed low address with a value between 0 and 7, so the consequence is a fatal memory fault (BusFault or corrupted low memory leading to a fault) rather than a usable memory-corruption primitive: the device crashes or resets. Confidentiality and integrity are not affected. The fix moves the store below the guard and validates the context pointer itself instead of the return code, so the context is only touched once it is known to be valid.
Published: 2026-09-28
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Availability loss due to device crash from a null pointer dereference
Action: Patch Immediately
AI Analysis

Impact

The flaw resides in the Zephyr LwM2M client's handling of CoAP Block1 messages. When the static pool of block contexts is exhausted, the client writes a block size into a pointer that may be NULL, triggering a fatal memory fault (BusFault or similar). The attacker cannot read or modify data; the only consequence is a crash or reset, leading to loss of availability but no confidentiality or integrity compromise.

Affected Systems

The vulnerability affects any device running the Zephyr Project’s Zephyr real‑time operating system that includes the unpatched LwM2M client code. Devices that compile with the default CONFIG_LWM2M_NUM_BLOCK1_CONTEXT value of three, and that do not enable DTLS, are susceptible before the commit that adds the guard.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The exploit requires the ability to send UDP packets to the LwM2M client socket; it does not require authentication if the client operates in NoSec mode. The likely attack vector is inferred from the description: an attacker can initiate three concurrent block-wise writes on distinct object paths, exhausting the context pool, and then begin a fourth write on a new path, causing the unguarded dereference. No credential or network filtering is needed unless DTLS is enabled. The EPSS metric is not available, and the vulnerability is not listed in the CISA KEV catalog, so known exploitation probability is uncertain but the conditions are straightforward.

Generated by OpenCVE AI on September 29, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Zephyr to the latest release that includes the block‑context guard (apply commit e61790f776863032925e96819f84cafc9a958b8a or newer).
  • If an upgrade is not immediately possible, reduce the number of concurrent Block1 contexts by setting CONFIG_LWM2M_NUM_BLOCK1_CONTEXT to 1 or disable large‑message support.
  • Enable DTLS on the LwM2M client (CONFIG_LWM2M_DTLS_SUPPORT) or otherwise enforce authenticated connections to block unauthenticated block‑wise writes.

Generated by OpenCVE AI on September 29, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Mon, 28 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block size with block_ctx->ctx.block_size = block_size before inspecting the return code. init_block_ctx() sets the caller's pointer to NULL and returns -ENOMEM when no entry of the static block1_contexts[] pool is free or timed out, so that store dereferences a NULL pointer. The pool holds CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries (default 3) and an entry is only reclaimed once its transfer completes, fails, or ages past 30 seconds. A peer that reaches the client's LwM2M socket can therefore start three block-wise writes on three distinct object paths with the CoAP More bit set and leave them incomplete, then send the first block of a fourth write on a new path to reach the unguarded dereference. Reachability is gated only by the connected UDP socket's source-address filter unless CONFIG_LWM2M_DTLS_SUPPORT is enabled — which has no default — so in a NoSec deployment an on-path or address-spoofing attacker needs no credentials; the same sequence is also reachable from a bootstrap or lower-trust server, and can be hit accidentally by a legitimate server running four concurrent block transfers. The write targets a fixed low address with a value between 0 and 7, so the consequence is a fatal memory fault (BusFault or corrupted low memory leading to a fault) rather than a usable memory-corruption primitive: the device crashes or resets. Confidentiality and integrity are not affected. The fix moves the store below the guard and validates the context pointer itself instead of the return code, so the context is only touched once it is known to be valid.
Title NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-28T23:25:24.971Z

Reserved: 2026-08-03T21:22:11.665Z

Link: CVE-2026-18746

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T00:17:04.347

Modified: 2026-09-29T00:17:04.347

Link: CVE-2026-18746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T01:30:09Z

Weaknesses