What is CVE-2026-10773?
A critical vulnerability exists in the DHCPv4 client component of Zephyr RTOS. The `net_dhcpv4_msg_type_name()` function uses a faulty bounds check (`sizeof` instead of `ARRAY_SIZE`), leading to an out-of-bounds read. This can be exploited by a malicious DHCP server to cause information leakage or system crashes. Users are advised to apply the security update from the Zephyr project immediately.
Azərbaycanca: Zephyr RTOS-un DHCPv4 müştəri komponentində kritik zəiflik aşkarlanıb. `net_dhcpv4_msg_type_name()` funksiyasındakı səhv sərhəd yoxlaması (`sizeof` əvəzinə `ARRAY_SIZE` istifadə edilməməsi) massivdən kənar oxumağa (out-of-bounds read) səbəb olur. Bu, DHCP server tərəfindən göndərilən xüsusi hazırlanmış paketlər vasitəsilə məlumat sızmasına və ya sistemin çökməsinə yol aça bilər. İstifadəçilərə ən qısa zamanda Zephyr layihəsinin təqdim etdiyi təhlükəsizlik yeniləməsini tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
In which component of Zephyr RTOS was CVE-2026-10773 discovered?
This critical vulnerability was discovered in the DHCPv4 client component of Zephyr RTOS.
What can an attacker achieve by exploiting CVE-2026-10773?
By using specially crafted DHCP packets, an attacker can cause information leakage or system crashes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.