What is CVE-2026-11811?
CVE-2026-11811 affects the UpdateHub OTA update client, where a socket descriptor leak occurs in the start_coap_client() function. On connection setup failures, the CoAP/DTLS socket is not properly closed due to incorrect error handling, leading to potential resource exhaustion. Affected users should update the UpdateHub component to the latest patched version.
Azərbaycanca: CVE-2026-11811 UpdateHub OTA yeniləmə müştərisində aşkar edilib. start_coap_client() funksiyasında CoAP/DTLS socket descriptor sızması baş verir ki, bu da uğursuz bağlantı qurma cəhdləri zamanı resursların düzgün azad edilməməsinə səbəb olur. Təsirə məruz qalan sistemlərdə socket sızmasının qarşısını almaq üçün UpdateHub komponentini ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
In which function of UpdateHub does CVE-2026-11811 occur?
The vulnerability occurs in the start_coap_client() function, where a CoAP/DTLS socket descriptor leak happens on connection setup failure.
What is recommended to mitigate the impact of CVE-2026-11811?
It is recommended to update the UpdateHub component to the latest version to prevent the socket leak.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.