CVE-2026-18746: NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted
parsewriteop() in subsys/net/lib/lwm2m/lwm2mmessagehandling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called initblockctx() and then immediately stored the peer-selected block size with blockctx->ctx.blocksize = blocksize before inspecting the return code. initblockctx() sets the caller's pointer to NULL and returns -ENOMEM when no entry of the static block1contexts[] pool is free or timed out, so that store dereferences a NULL pointer.
The pool holds CONFIGLWM2MNUMBLOCK1CONTEXT entries (default 3) and an entry is only reclaimed once its transfer completes, fails, or ages past 30 seconds. A peer that reaches the client's LwM2M socket can therefore start three block-wise writes on three distinct object paths with the CoAP More bit set and leave them incomplete, then send the first block of a fourth write on a new path to reach the unguarded dereference. Reachability is gated only by the connected UDP socket's source-address filter unless CONFIGLWM2MDTLSSUPPORT is enabled — which has no default — so in a NoSec deployment an on-path or address-spoofing attacker needs no credentials; the same sequence is also reachable from a bootstrap or lower-trust server, and can be hit accidentally by a legitimate server running four concurrent block transfers.
The write targets a fixed low address with a value between 0 and 7, so the consequence is a fatal memory fault (BusFault or corrupted low memory leading to a fault) rather than a usable memory-corruption primitive: the device crashes or resets. Confidentiality and integrity are not affected. The fix moves the store below the guard and validates the context pointer itself instead of the return code, so the context is only touched once it is known to be valid.
Affected Software
Event History
Frequently Asked Questions
Is a default LwM2M client configuration susceptible to pool exhaustion?
Yes. The Block1 context pool defaults to CONFIG_LWM2M_NUM_BLOCK1_CONTEXT entries, which is 3 by default. An attacker can occupy those entries with incomplete block-wise transfers before triggering the condition with another transfer on a different object path.
What network access does an attacker need?
The attacker must be able to reach the client's LwM2M UDP socket. In a NoSec deployment, the source-address filter is the only reachability gate, so an on-path or source-address-spoofing attacker needs no credentials.
What request pattern triggers the condition?
The attacker starts block-wise CoAP WRITE or CREATE requests on distinct object paths with the More bit set, leaving the transfers incomplete. After the available Block1 contexts are occupied, the first block of another write on a new path reaches the unguarded NULL-pointer store.