CVE-2026-18747 | Zephyr Project up to 4.4.1 Serial Transport serial_util.c mcumgr_serial_extract_len out-of-bounds (EUVD-2026-88575)

SecurityVulns

A vulnerability labeled as problematic has been found in Zephyr Project Zephyr up to 4.4.1. Impacted is the function mcumgr_serial_extract_len of the file subsys/mgmt/mcumgr/transport/src/serial_util.c of the component Serial Transport. Such manipulation leads to out-of-bounds read.

This vulnerability is listed as CVE-2026-18747. The attack must be carried out locally. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More