CVE-2026-17050 | ZephyrProject Zephyr up to 4.4.1 USB Host Stack usbh_device.c usbh_device_set_configuration cfg_desc double free

SecurityVulns

A vulnerability, which was classified as very critical, has been found in ZephyrProject Zephyr up to 4.4.1. Impacted is the function usbh_device_set_configuration of the file subsys/usb/host/usbh_device.c of the component USB Host Stack. Performing a manipulation of the argument cfg_desc results in double free.

This vulnerability is identified as CVE-2026-17050. The attack is only possible with local access. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More