Zephyr LTS v3.7.3-rc1
Pre-release
Pre-release
This is an LTS maintenance release with fixes.
Security Vulnerability Related
The following CVEs are addressed by this release:
More detailed information can be found in: https://docs.zephyrproject.org/latest/security/vulnerabilities.html
- CVE-2026-2411 — Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values (Impacts: >= 2.6.0, <= 4.4.1)
- CVE-2026-7007 — Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image (Impacts: >= 3.5.0, <= 4.4.1)
- CVE-2026-7656 — Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack (Impacts: <= 4.4.0)
- CVE-2026-8718 — Under embargo until 2026-08-08
- CVE-2026-9263 — Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets (Impacts: >= 3.3.0, <= 4.4.1)
- CVE-2026-9728 — Under embargo until 2026-08-23
- CVE-2026-10634 — Use-after-free in Zephyr native TCP net_tcp_foreach() due to dropping tcp_lock during the callback (Impacts: >= 3.6.0, <= 4.4.1)
- CVE-2026-10636 — Use-after-free in Zephyr IPv4 IGMP send path (igmp_send) (Impacts: >= 2.6.0, <= 4.4.1)
- CVE-2026-10637 — Use-after-free of net_pkt in IPv6 MLD send path triggerable by a link-local MLD Query (Impacts: >= 1.12.0, <= 4.4.0)
- CVE-2026-10638 — Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10639 — Use-after-free reading net_pkt_iface() of a sent ICMPv4 echo-reply packet in icmpv4_handle_echo_request() (Impacts: >= 4.2.0, <= 4.4.1)
- CVE-2026-10640 — Use-after-free reading net_pkt iface after send in IPv6 Neighbor Discovery (ipv6_nbr.c) (Impacts: >= 3.3.0, <= 4.4.1)
- CVE-2026-10641 — Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values) (Impacts: >= 3.7.0)
- CVE-2026-10643 — Out-of-bounds heap write in Zephyr recvmsg() ancillary-data path (insert_pktinfo undersizes the control-buffer capacity check) (Impacts: >= 4.0.0, <= 4.4.1)
- CVE-2026-10645 — Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image (Impacts: <= 4.4)
- CVE-2026-10652 — Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated rdlength) (Impacts: >= 4.3.0, <= 4.4.1)
- CVE-2026-10654 — RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic (Impacts: >= 1.6.0, <= 4.4.0)
- CVE-2026-10657 — Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL) (Impacts: >= 1.10.0, <= 4.4.1)
- CVE-2026-10658 — Out-of-bounds access in Bluetooth ISO receive (bt_iso_recv) due to missing SDU-header length validation (Impacts: <= 4.4.0)
- CVE-2026-10660 — Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption (Impacts: >= 3.6.0, <= 4.4.0)
- CVE-2026-10666 — Stack buffer overflow in net_ipaddr_parse() IPv4 address-with-port parsing in subsys/net/ip/utils.c (Impacts: >1.10.0)
- CVE-2026-10667 — SMP use-after-free in Zephyr CONFIG_USERSPACE dynamic kernel-object tracking, reachable from unprivileged user threads (Impacts: <= 4.3)
- CVE-2026-10669 — Xtensa MPU arch_buffer_validate() integer-overflow lets a user thread bypass syscall pointer validation (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10670 — User-triggerable kernel NULL-pointer dereference (DoS) in k_thread_name_copy() syscall verifier (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10672 — Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI) (Impacts: v4.3.0, v4.2.1, v3.7.1)
- CVE-2026-10673 — Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10674 — DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled (Impacts: >= 3.7.0, <= 4.4.1)
- CVE-2026-10675 — Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS) (Impacts: >= 3.5.0, <= 4.4.1)
- CVE-2026-10677 — Kernel heap memory leak in z_vrfy_k_poll() lets an unprivileged user thread exhaust the kernel resource pool (Impacts: >= 1.12.0, <= 4.4.1)
- CVE-2026-10679 — Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS) (Impacts: >= 1.8.0, <= 4.4.1)
- CVE-2026-10680 — Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via uint16_t length underflow (Impacts: >= 4.2.0, < 4.3.1; >= 4.4.0, <= 4.4.1)
- CVE-2026-10681 — SMP race in thread_idx_alloc() lets concurrent k_object_alloc(K_OBJ_THREAD) callers share a kernel-object permission slot (Impacts: >= 2.0.0, <= 4.4.1)
- CVE-2026-10682 — Out-of-bounds write in Zephyr log_filter_set syscall verifier reachable from userspace (Impacts: >= 3.0.0, <= 4.4.1)
- CVE-2026-10685 — Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler (Impacts: >= 2.4.0, <= 4.4.1)
- CVE-2026-10686 — Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers (Impacts: >= 1.8.0, <= 4.4.1)
- CVE-2026-10773 — Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name) (Impacts: >= 1.7.0, <= 4.4.1)
- CVE-2026-10774 — PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS (Impacts: >= 3.6.0, <= 4.4.1)
- CVE-2026-10849 — Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body (Impacts: >= 2.4.0, <= 4.4.1)
- CVE-2026-11742 — Under embargo until 2026-08-07
- CVE-2026-11809 — Under embargo until 2026-08-08
- CVE-2026-11810 — Under embargo until 2026-08-08
- CVE-2026-11811 — Under embargo until 2026-08-08
- CVE-2026-11812 — Under embargo until 2026-08-08
- CVE-2026-11985 — Under embargo until 2026-08-09
- CVE-2026-12232 — Under embargo until 2026-08-11
- CVE-2026-12233 — Under embargo until 2026-08-11
- CVE-2026-12234 — Under embargo until 2026-08-11
- CVE-2026-12236 — Under embargo until 2026-08-13
- CVE-2026-12363 — Under embargo until 2026-08-14
- CVE-2026-12519 — Under embargo until 2026-08-16
- CVE-2026-12520 — Under embargo until 2026-08-16
- CVE-2026-12521 — Under embargo until 2026-08-16
- CVE-2026-12522 — Under embargo until 2026-08-16
- CVE-2026-12630 — Under embargo until 2026-08-16
- CVE-2026-12631 — Under embargo until 2026-08-16
- CVE-2026-12632 — Under embargo until 2026-08-16
- CVE-2026-12633 — Under embargo until 2026-08-16
- CVE-2026-12634 — Under embargo until 2026-08-16
- CVE-2026-12999 — Under embargo until 2026-08-22
- CVE-2026-13213 — Under embargo until 2026-08-23
- CVE-2026-13215 — Under embargo until 2026-08-23
- CVE-2026-13478 — Under embargo until 2026-08-25
- CVE-2026-13479 — Under embargo until 2026-08-26
- CVE-2026-13480 — Under embargo until 2026-08-26
- CVE-2026-14368 — Under embargo until 2026-08-30
- CVE-2026-15460 — Under embargo until 2026-09-07
- CVE-2026-15892 — Under embargo until 2026-09-12
- CVE-2026-15893 — Under embargo until 2026-09-13
- CVE-2026-15894 — Under embargo until 2026-09-13
- CVE-2026-15923 — Under embargo until 2026-09-13
- CVE-2026-15924 — Under embargo until 2026-09-13
- CVE-2026-16148 — Under embargo until 2026-09-14
- CVE-2026-16511 — Under embargo until 2026-09-18
- CVE-2026-16512 — Under embargo until 2026-09-18
- CVE-2026-16513 — Under embargo until 2026-09-18
- CVE-2026-16514 — Under embargo until 2026-09-18
- CVE-2026-16515 — Under embargo until 2026-09-18
- CVE-2026-17051 — Under embargo until 2026-09-20
- CVE-2026-17052 — Under embargo until 2026-09-20
- CVE-2026-17053 — Under embargo until 2026-09-20
- CVE-2026-18413 — Under embargo until 2026-09-26
- CVE-2026-18414 — Under embargo until 2026-09-26
- CVE-2026-18415 — Under embargo until 2026-09-26
- CVE-2026-18416 — Under embargo until 2026-09-26
- CVE-2026-18746 — Under embargo until 2026-09-28
- CVE-2026-18747 — Under embargo until 2026-09-28
- CVE-2026-19186 — Under embargo until 2026-10-04
Mbed TLS
Mbed TLS was updated to version 3.6.7 (from 3.6.6). It addresses a number of CVEs. Release notes can be found at: https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-3.6.7
Mbed TLS 3.6 is an LTS release that will be supported with security and bug fixes until March 2027.
Issues fixed
These GitHub issues were addressed since the previous 3.7.2 tagged release:
- #87223 - net: if: NET_EVENT_L4_CONNECTED is no longer sent when !IPV4_ACD and/or !IPV6_DAD
- #99527 - subsys: net/lib/ptp: wrong use of CONTAINER_OF with struct ptp_tlv_mgmt *
- #103831 - Add mcxc242 lpuart dma support (async api)
- #105540 - STM32G0C1RET3 (Zephyr WWDG): EWI Callback Not Invoked
- #106895 - [v3.7-branch] update Mbed TLS to 3.6.6
- #106991 - net: tcp: use-after-free in net_tcp_foreach() causes bus fault
- #107900 - net: ipv6: Neighbor Discovery packets validation is incorrect
- #107920 - net: icmp: assert triggered sending icmp echo response with CONFIG_NET_STATISTICS=y
- #107928 - [backport] net: lib: http_server: Fix in websocket must be back ported to 3.7 and 4.3
- #108793 - kernel: init: main thread not tagged K_FP_REGS when CONFIG_FPU && CONFIG_FPU_SHARING
- #108835 - adin2111: Communication gets stuck after high bandwidth transfer
- #108846 - Validate DNS rdata length in dns_unpack_answer
- #108963 - net: lwm2m: URI string may be unterminated in FW pull mode
- #109053 - native_sim: FUSE files are opened write-only
- #109063 - The issue in Bluetooth Mesh solicitation PDU parsing
- #109128 - fs: backend file resource leak when fs_open with FS_O_TRUNC fails during truncate
- #109133 - Undefined bitwise shift behavior in PTP port management interval handling
- #109257 - [backport] xtensa: mpu: fix arch_buffer_validate() if overflow
- #109403 - net: icmpv6: missing source address guard in net_icmpv6_send_error (RFC 4443 2.4(e.6))
- #109620 - [backport] Bluetooth: Controller: Fix OOB read in ISOAL
- #109942 - Security advisory GHSA-8hrf-pfww-83v9 / CVE-2025-12890 fix not available for Zephyr 3.7
- #109957 - Kernel: Backport k_poll() memory leak fix to 3.7
- #109958 - Kernel: userspace: Backport validate_kernel_object type/init to 3.7
- #109960 - backport: kernel: add kobj NULL check in k_thread_name_copy()
- #110032 - [backport] fs: ext2: validate directory entry structure before traversal #108226
- #110645 - [Backport] net: sockets: recvmsg() ancillary-data capacity check undercounts cmsg size
- #110762 - bluetooth: classic: hfp_hf: cind_handle_values() writes past ind_table on a long +CIND list
- #110854 - bluetooth: classic: rfcomm: session stuck and L2CAP channel leaked when both sides disconnect simultaneously
- #110866 - net: dns:
.localsuffix check reads past the end of the hostname string - #110915 - pb-adv bearer resets the protocol timer unconditionally
- #110956 - Bluetooth: ISO: bt_iso_recv() pulls the SDU header without checking buf->len
- #110967 - Bluetooth: BAP: Broadcast Assistant shares one att_buf across all connections
- #111016 - kernel: userspace: dynamic kernel-object list freed under a different lock than it is traversed
- #111031 - tests/drivers/can/api/drivers.can.api fails on mutex
- #111032 - tests/net/lib/tls_credentials/net.tls_credentials.trusted_tfm fails on mutex
- #111119 - drivers: spi: dw: spi_dw_configure() uses config->frequency as a divisor without validating it
- #111216 - [Backport v3.7-branch] Failed to backport #109875
- #111238 - net: http: server: spurious zsock_poll() return of 0 leaks sockets and corrupts the kernel timeout list
- #111404 - bluetooth: host: classic: l2cap_br: conf req/rsp validate minimum size against the wrong length
- #111407 - kernel: userspace: thread_idx_alloc() races on SMP and can hand out duplicate thread indices
- #111416 - logging: z_vrfy_log_filter_set() accepts a negative src_id and indexes outside log_dynamic
- #111427 - bluetooth: host: gatt_write_ccc_rsp() uses subscription params after releasing them
- #111431 - net: ip: forwarded packets keep their original TTL / hop-limit (no decrement on the routing path)
- #111534 - Bluetooth: GATT: notify/indicate checks the declaration's permissions, not the value's, when passed a characteristic declaration
- #111936 - fs: ext2: Avoid using 0 value inode and block per group in calculations
- #112204 - net: sockets: recvmsg() ancillary write checks total buffer, not room at the chosen slot
- #112211 - Bluetooth: BAP: UC: NULL stream->group dereference on QoS Configured notification
- #112325 - Out-of-bounds read in PTP receive path: unchecked 4-bit message type indexes
- #112421 - net: dhcp: name-lookup bounds checks use sizeof() instead of ARRAY_SIZE()
- #112427 - mgmt: hawkbit: 1-byte heap overrun when NUL-terminating the response buffer
- #112435 - kernel: k_queue_peek_head()/k_queue_peek_tail() dereference a node without holding the queue lock
- #112441 - mgmt: updatehub: socket leak, NULL deref, and concurrency bugs in the OTA client
- #112616 - net: sockets: userspace sendmsg/recvmsg verifiers re-read live user msghdr after copying it
- #112743 - drivers: dai: intel: alh: get_properties reads out of bounds for an invalid stream_id
- #112782 - mgmt/settings: heap buffers leaked on access-hook and OOM paths in settings read/write/delete
- #112838 - Bluetooth: Host: GATT: parse_read_std_char_desc() loops forever when a Read By Type Response has len 0
- #112927 - lorawan: frag_transport: DataFragment index 0 underflows to an out-of-bounds decoder write
- #113039 - drivers: modem: hl7800 and wncm14a2a AT-response handlers write past fixed stack buffers
- #113043 - net: 6lo: get_ihpc_inlined_size() reads past da_inline_size_table for reserved destination modes
- #113048 - net: ipv6: handle_ra_6co() underflows memset length for context_len > 128
- #113216 - The issue in Bluetooth Mesh solicitation PDU decryption
- #113266 - kernel: thread: thread_obj_validate() fails to oops a denied k_thread_join/k_thread_abort
- #113295 - settings: nvs: NUL terminator is written past the end of the name buffer
- #113299 - net: route: net_route_packet_if() forwards packets without decrementing the hop limit
- #113303 - wifi: airoc: TX net_buf is leaked when whd_network_send_ethernet_data() fails
- #113307 - mbox: userspace: z_vrfy_mbox_send validates msg->data then forwards the mutable userspace pointer
- #113324 - fs: ext2: mount does not validate superblock s_log_block_size
- #113346 - bluetooth: audio: has: notification work runs with NULL attributes when a bonded peer reconnects before bt_has_register()
- #113350 - fs: ext2: block-bitmap validation reads past the bitmap buffer for an oversized s_blocks_count
- #113354 - lorawan: services parse downlink commands without checking remaining payload length
- #113372 - update Mbed TLS to 3.6.7
- #113443 - net: lwm2m: JSON get_string() writes the NUL terminator one byte past the buffer
- #113684 - [backport] net: ipv6: Zero reachable time from Router Advertisement assertion
- #113698 - bluetooth: classic: l2cap: BR/EDR receive path processes data on channels that are not yet established
- #113729 - sd: sdio: byte-I/O loop spins forever when a card reports max_blk_size == 0
- #113735 - net: sockets: tls: concurrent client sockets race on the shared session cache
- #113748 - net: sockets/tls: TLS_DTLS_PEER_CID_VALUE getsockopt writes past the caller's buffer
- #113845 - drivers: udc: it82xx2: OUT-transfer buffer reuse and suspend-work re-init corrupt kernel state
- #114320 - rtio: syscall verifiers dereference unvalidated user pointers in sqe_cancel() and sqe_copy_in_get_handles()
- #114337 - net: gptp: receive path dereferences and iterates past the received packet data
- #114506 - drivers: tgpio: tgpio_pin_read_ts_ec handler does not validate its output pointers
- #114514 - drivers: ipm: ipm_sedi: inbound message length is not validated before the RX copy
- #114522 - smbus: remove_cb syscalls forward an unvalidated user pointer into the driver
- #114895 - net: ieee802154: unchecked copy into the TX frame buffer, and one MAC frame per net_buf
- #114902 - net: coap: match_path_uri() reads past the end of the Uri-Query value
- #114978 - drivers: adc: MCUX LPADC and MAX32 write samples past the end of the adc_sequence buffer
- #115025 - mgmt: mcumgr: transport: serial: Check for minimum size of data
- #115223 - net: lwm2m: NULL dereference in parse_write_op() when the block1 context pool is exhausted