CVE-2026-18417 | Zephyr Project up to 4.4.1 BSD Socket Layer sockets_inet.c user_data null pointer dereference (EUVD-2026-88573)
A vulnerability marked as critical has been reported in Zephyr Project Zephyr up to 4.4.1. The affected element is the function zsock_accepted_cb/zsock_received_cb/zsock_connected_cb/zsock_close_ctx of the file subsys/net/lib/sockets/sockets_inet.c of the component BSD Socket Layer. Performing a manipulation of the argument user_data results in null pointer dereference.
This vulnerability is cataloged as CVE-2026-18417. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More