CVE-2026-15891 | Zephyr Project up to 4.4.1 Keepalive mqtt_sn.c process_ping null pointer dereference

SecurityVulns

A vulnerability described as critical has been identified in Zephyr Project Zephyr up to 4.4.1. This issue affects the function process_ping of the file subsys/net/lib/mqtt_sn/mqtt_sn.c of the component Keepalive Handler. Such manipulation leads to null pointer dereference.

This vulnerability is uniquely identified as CVE-2026-15891. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More