CVE-2026-9728 | Zephyr Project up to 4.4.1 Syscall Verifier mbox_handlers.c z_vrfy_mbox_send data/size toctou
A vulnerability categorized as problematic has been discovered in Zephyr Project Zephyr up to 4.4.1. Impacted is the function z_vrfy_mbox_send of the file drivers/mbox/mbox_handlers.c of the component Syscall Verifier. Executing a manipulation of the argument data/size can lead to time-of-check time-of-use.
This vulnerability is handled as CVE-2026-9728. It is possible to launch the attack on the local host. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More