CVE-2026-12051 | Zephyr up to 4.4.x USB DFU Class usbd_dfu.c handle_download buf null pointer dereference
A vulnerability labeled as critical has been found in Zephyr up to 4.4.x. Affected by this vulnerability is the function handle_download of the file subsys/usb/device_next/class/usbd_dfu.c of the component USB DFU Class. Such manipulation of the argument buf leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-12051. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More