<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 04:07:24 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-15891 — NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gateway</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-15891</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; zephyrproject zephyr&lt;/p&gt;
&lt;p&gt;The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&amp;amp;client-&amp;gt;gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents.&lt;/p&gt;
&lt;p&gt;The code then dereferences the NULL gw (gw-&amp;gt;gw_id) and passes it to mqtt_sn_gw_destroy(), reaching k_mem_slab_free(&amp;amp;gateways, NULL). With CONFIG_MEM_SLAB_POINTER_VALIDATE enabled this triggers k_panic(); in the default configuration it performs a write through the NULL pointer ((char )mem = slab-&amp;gt;free_list;) and corrupts the slab free list. The outcome is a crash/kernel panic or, on targets where address 0 is writable, silent memory-allocator corruption.&lt;/p&gt;
&lt;p&gt;The vulnerable branch runs whenever the connected MQTT-SN gateway fails to answer keepalive PINGREQs for the configured number of retries. This condition is controlled by the remote peer: a malicious or compromised gateway, or an on-path/adjacent attacker that advertises itself as a gateway and then stops responding (or blackholes the real gateway&amp;#39;s PINGRESPs), forces the client into the defect. MQTT-SN runs over UDP and no authentication is required.&lt;/p&gt;
&lt;p&gt;The impact is a remotely triggerable denial of service (availability) of the affected MQTT-SN client; there is no attacker-controlled data written. The sibling remover process_advertise() uses SYS_SLIST_F…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; zephyrproject zephyr&lt;/p&gt;
&lt;p&gt;The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&amp;amp;client-&amp;gt;gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents.&lt;/p&gt;
&lt;p&gt;The code then dereferences the NULL gw (gw-&amp;gt;gw_id) and passes it to mqtt_sn_gw_destroy(), reaching k_mem_slab_free(&amp;amp;gateways, NULL). With CONFIG_MEM_SLAB_POINTER_VALIDATE enabled this triggers k_panic(); in the default configuration it performs a write through the NULL pointer ((char )mem = slab-&amp;gt;free_list;) and corrupts the slab free list. The outcome is a crash/kernel panic or, on targets where address 0 is writable, silent memory-allocator corruption.&lt;/p&gt;
&lt;p&gt;The vulnerable branch runs whenever the connected MQTT-SN gateway fails to answer keepalive PINGREQs for the configured number of retries. This condition is controlled by the remote peer: a malicious or compromised gateway, or an on-path/adjacent attacker that advertises itself as a gateway and then stops responding (or blackholes the real gateway&amp;#39;s PINGRESPs), forces the client into the defect. MQTT-SN runs over UDP and no authentication is required.&lt;/p&gt;
&lt;p&gt;The impact is a remotely triggerable denial of service (availability) of the affected MQTT-SN client; there is no attacker-controlled data written. The sibling remover process_advertise() uses SYS_SLIST_F…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-15891</guid>
    </item>
  </channel>
</rss>
