CVE-2026-12365 | ZephyrProject Zephyr up to 4.4.x Work Queue kernel/work.c work_timeout dticks/flags use after free

SecurityVulns

A vulnerability was found in ZephyrProject Zephyr up to 4.4.x and classified as very critical. Affected by this issue is the function work_timeout of the file kernel/work.c of the component Work Queue. The manipulation of the argument dticks/flags results in use after free.

This vulnerability is reported as CVE-2026-12365. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More