CVE-2026-18746 | Zephyr Project up to 4.4.x LwM2M lwm2m_message_handling.c parse_write_op null pointer dereference (EUVD-2026-88574)

SecurityVulns

A vulnerability identified as critical has been detected in Zephyr Project Zephyr up to 4.4.x. This issue affects the function parse_write_op of the file subsys/net/lib/lwm2m/lwm2m_message_handling.c of the component LwM2M. This manipulation causes null pointer dereference.

This vulnerability is tracked as CVE-2026-18746. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More