Impact
The flaw resides in the Zephyr LwM2M client's handling of CoAP Block1 messages. When the static pool of block contexts is exhausted, the client writes a block size into a pointer that may be NULL, triggering a fatal memory fault (BusFault or similar). The attacker cannot read or modify data; the only consequence is a crash or reset, leading to loss of availability but no confidentiality or integrity compromise.
Affected Systems
The vulnerability affects any device running the Zephyr Project’s Zephyr real‑time operating system that includes the unpatched LwM2M client code. Devices that compile with the default CONFIG_LWM2M_NUM_BLOCK1_CONTEXT value of three, and that do not enable DTLS, are susceptible before the commit that adds the guard.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The exploit requires the ability to send UDP packets to the LwM2M client socket; it does not require authentication if the client operates in NoSec mode. The likely attack vector is inferred from the description: an attacker can initiate three concurrent block-wise writes on distinct object paths, exhausting the context pool, and then begin a fourth write on a new path, causing the unguarded dereference. No credential or network filtering is needed unless DTLS is enabled. The EPSS metric is not available, and the vulnerability is not listed in the CISA KEV catalog, so known exploitation probability is uncertain but the conditions are straightforward.
OpenCVE Enrichment