CVE-2026-18746: NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted

Published Sep 28, 2026
·
Updated

parsewriteop() in subsys/net/lib/lwm2m/lwm2mmessagehandling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called initblockctx() and then immediately stored the peer-selected block size with blockctx->ctx.blocksize = blocksize before inspecting the return code. initblockctx() sets the caller's pointer to NULL and returns -ENOMEM when no entry of the static block1contexts[] pool is free or timed out, so that store dereferences a NULL pointer.

The pool holds CONFIGLWM2MNUMBLOCK1CONTEXT entries (default 3) and an entry is only reclaimed once its transfer completes, fails, or ages past 30 seconds. A peer that reaches the client's LwM2M socket can therefore start three block-wise writes on three distinct object paths with the CoAP More bit set and leave them incomplete, then send the first block of a fourth write on a new path to reach the unguarded dereference. Reachability is gated only by the connected UDP socket's source-address filter unless CONFIGLWM2MDTLSSUPPORT is enabled — which has no default — so in a NoSec deployment an on-path or address-spoofing attacker needs no credentials; the same sequence is also reachable from a bootstrap or lower-trust server, and can be hit accidentally by a legitimate server running four concurrent block transfers.

The write targets a fixed low address with a value between 0 and 7, so the consequence is a fatal memory fault (BusFault or corrupted low memory leading to a fault) rather than a usable memory-corruption primitive: the device crashes or resets. Confidentiality and integrity are not affected. The fix moves the store below the guard and validates the context pointer itself instead of the return code, so the context is only touched once it is known to be valid.

Affected Software

1 affected component
Zephyr Project Zephyr LwM2M client

Event History

Sep 28, 2026
CVE Published
via MITRE·11:25 PM
Data Sourced
via MITRE·11:25 PM
DescriptionSeverityWeakness
Sep 29, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Is a default LwM2M client configuration susceptible to pool exhaustion?

Yes. The Block1 context pool defaults to CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries, which is 3 by default. An attacker can occupy those entries with incomplete block-wise transfers before triggering the condition with another transfer on a different object path.

2

What network access does an attacker need?

The attacker must be able to reach the client's LwM2M UDP socket. In a NoSec deployment, the source-address filter is the only reachability gate, so an on-path or source-address-spoofing attacker needs no credentials.

3

What request pattern triggers the condition?

The attacker starts block-wise CoAP WRITE or CREATE requests on distinct object paths with the More bit set, leaving the transfers incomplete. After the available Block1 contexts are occupied, the first block of another write on a new path reaches the unguarded NULL-pointer store.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203