CVE-2026-12366 | Zephyr Project up to 4.4.x Timer Cleanup userspace.c unref_check use after free
A vulnerability was found in Zephyr Project Zephyr up to 4.4.x. It has been classified as very critical. This affects the function unref_check of the file kernel/userspace/userspace.c of the component Timer Cleanup. This manipulation causes use after free.
This vulnerability appears as CVE-2026-12366. The attack requires local access. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More