CVE-2026-12234 | Zephyr Project up to 4.4.1 Syscall Verifier sockets.c z_vrfy_zsock_sendmsg/z_vrfy_zsock_recvmsg msg_iovlen toctou
A vulnerability was found in Zephyr Project Zephyr up to 4.4.1 and classified as very critical. This affects the function z_vrfy_zsock_sendmsg/z_vrfy_zsock_recvmsg of the file subsys/net/lib/sockets/sockets.c of the component Syscall Verifier. Executing a manipulation of the argument msg_iovlen can lead to time-of-check time-of-use.
The identification of this vulnerability is CVE-2026-12234. The attack can only be executed locally. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More