What is CVE-2026-11985?
This vulnerability arises on Zephyr ARM port when hardware FPU is enabled, as FP_HARDABI/FP_SOFTABI configs allow the compiler to emit hardware FP instructions even in functions not using floating-point types, potentially causing unexpected hardware exceptions. Affected systems should review FPU usage and apply the appropriate patch.
Azərbaycanca: Bu boşluq Zephyr ARM platformasında aparat üzən nöqtə (hardware FPU) aktiv olduqda ortaya çıxır; FP_HARDABI/FP_SOFTABI konfiqurasiyaları kompilyatora üzən nöqtə tipləri istifadə olunmayan funksiyalarda belə aparat FP təlimatları yaymağa icazə verir. Nəticədə gözlənilməz aparat istisnaları baş verə bilər. Təsirə məruz qalan sistemlərdə FPU istifadəsini yoxlamaq və müvafiq yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Zephyr
FAQ1
Under what conditions does CVE-2026-11985 occur on the Zephyr ARM platform?
This vulnerability occurs when hardware FPU is enabled and FP_HARDABI/FP_SOFTABI configurations are used, because these configs allow the compiler to emit hardware FP instructions even in functions not using floating-point types, which can cause unexpected hardware exceptions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.