CVE-2026-5590
בינונית 5.3
תיאור (מקור, אנגלית)
A race condition during TCP connection teardown can cause tcp_recv() to operate on a connection that has already been released. If tcp_conn_search() returns NULL while processing a SYN packet, a NULL pointer derived from stale context data is passed to tcp_backlog_is_full() and dereferenced without validation, leading to a crash.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-27/7/2026
- CWE
- CWE-476
מוצרים מושפעים
zephyrproject: zephyr
קישורים
- https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-4vqm-pw2… ExploitPatchVendor Advisory