Sceawere

Vulnerability Detail

CVE-2026-18746UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LwM2M Null Pointer Dereference

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
7h ago
Vendor
zephyrproject
Product
zephyr
Attack Type
memory-safety
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init_block_ctx() and then immediately stored the peer-selected block size with block_ctx->ctx.block_size = block_size before inspecting the return code. init_block_ctx() sets the caller's pointer to NULL and returns -ENOMEM when no entry of the static block1_contexts[] pool is free or timed out, so that store dereferences a NULL pointer. The pool holds CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries (default 3) and an entry is only reclaimed once its transfer completes, fails, or ages past 30 seconds. A peer that reaches the client's LwM2M socket can therefore start three block-wise writes on three distinct object paths with the CoAP More bit set and leave them incomplete, then send the first block of a fourth write on a new path to reach the unguarded dereference. Reachability is gated only by the connected UDP socket's source-address filter unless CONFIG_LWM2M_DTLS_SUPPORT is enabled — which has no default — so in a NoSec deployment an on-path or address-spoofing attacker needs no credentials; the same sequence is also reachable from a bootstrap or lower-trust server, and can be hit accidentally by a legitimate server running four concurrent block transfers. The write targets a fixed low address with a value between 0 and 7, so the consequence is a fatal memory fault (BusFault or corrupted low memory leading to a fault) rather than a usable memory-corruption primitive: the device crashes or resets. Confidentiality and integrity are not affected. The fix moves the store below the guard and validates the context pointer itself instead of the return code, so the context is only touched once it is known to be valid.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-09-29T00:17:04.347Z",
  "pubdate": "2026-09-29T00:17:04.347Z",
  "executiveSummary": "A Null Pointer Dereference vulnerability exists in the LwM2M library's message handling logic within the Zephyr project, specifically in the parse_write_op() function located in subsys/net/lib/lwm2m/lwm2m_message_handling.c.\nThe vulnerability allows an unauthenticated remote attacker to trigger a fatal system crash or device reset by exhausting the pre-allocated pool of block-wise transfer contexts.\nThis occurs because the code fails to validate the return status of init_block_ctx() before attempting to write to the resulting context structure. If the pool of CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries is exhausted, init_block_ctx() returns -ENOMEM and sets the context pointer to NULL, causing a null pointer dereference during the subsequent block_size assignment.\nThe impact is limited to a denial-of-service condition, resulting in a BusFault or device reset. No impact to confidentiality or integrity is observed as the write operation target is restricted to a fixed low address. The attack requires the ability to reach the LwM2M socket, and in NoSec deployments, this requires no credentials.",
  "technicalDetails": "The vulnerability is rooted in the improper error handling flow within parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c. When processing an inbound CoAP WRITE/CREATE request containing a Block1 option, the function invokes init_block_ctx() to initialize a context for the block-wise transfer.\nThe function init_block_ctx() utilizes a static pool of contexts defined by CONFIG_LWM2M_NUM_BLOCK1_CONTEXT (default value of 3). If the pool is exhausted or all existing entries are currently active, the function returns -ENOMEM and explicitly sets the provided pointer to NULL. The vulnerability arises because parse_write_op() proceeds to execute 'block_ctx->ctx.block_size = block_size' immediately after the function call without verifying whether the context pointer is valid.\nAn attacker can exploit this by initiating three concurrent, incomplete block-wise writes to distinct object paths, effectively saturating the available pool entries. Because these entries are only reclaimed after a transfer completes, fails, or ages out (30 seconds), the attacker has a sufficient window to send a first block of a fourth write request. This fourth request causes init_block_ctx() to fail and return NULL. The subsequent attempt to assign a value to the member of the null pointer results in a memory fault.\nThe network exposure is contingent on the LwM2M socket accessibility. In configurations where CONFIG_LWM2M_DTLS_SUPPORT is disabled, the vulnerability is accessible to any attacker capable of reaching the device's UDP port. Even in authenticated environments, a bootstrap server or a compromised lower-trust server could trigger this condition intentionally, and accidental triggering is possible in legitimate environments experiencing high concurrent load.\nThe exploit payload essentially involves a malformed CoAP Block1 request that triggers the context allocation failure. Upon dereferencing the null pointer, the processor encounters a hardware exception. On many embedded architectures, this results in a BusFault or an invalid memory access trap, which, in the absence of robust exception handling, forces a system reboot or hang, achieving a denial-of-service."
}
CVE-2026-18746: LwM2M Null Pointer Dereference (MEDIUM Severity, CVSS: 5.9) | Sceawere