What is CVE-2026-12051?
CVE-2026-12051 is a NULL pointer dereference vulnerability in the `handle_download()` function of Zephyr RTOS's experimental USB device_next stack. It affects the USB DFU class implementation and can be triggered via a crafted request, potentially leading to a system crash. Users are advised to avoid using this experimental feature until a security patch is applied.
Azərbaycanca: CVE-2026-12051, Zephyr RTOS-un eksperimental USB cihaz yığınında `handle_download()` funksiyasında aşkarlanan NULL pointer dereference zəifliyidir. USB DFU sinif tətbiqinə təsir edir və xüsusi hazırlanmış sorğu ilə sistemin çökməsinə səbəb ola bilər. İstifadəçilərə təhlükəsizlik yaması tətbiq olunana qədər bu eksperimental xüsusiyyəti deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-476; shared vendor: Zephyr
FAQ2
Which component of Zephyr RTOS is affected by CVE-2026-12051?
This vulnerability affects the USB DFU class implementation in the experimental USB device_next stack.
What is recommended to mitigate the risk of CVE-2026-12051 until a security patch is available?
Users are advised to disable this experimental feature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.