What is CVE-2026-12235?
CVE-2026-12235 involves improper handling of PLT/RELA relocation entries in Zephyr RTOS's llext subsystem when linking relocatable ELF extensions. This affects the Xtensa relocatable object path, potentially leading to security issues. Users should avoid loading untrusted relocatable extensions until a patch is applied.
Azərbaycanca: CVE-2026-12235 Zephyr RTOS-un llext alt sistemi ilə bağlıdır. Relocatable ELF uzantıları link edərkən PLT/RELA yerdəyişmə qeydlərinin səhv işlənməsi nəticəsində yaranır. Zephyr istifadəçiləri təhlükəsizlik yaması tətbiq olunana qədər etibarsız Xtensa relocatable obyektlərini yükləməməlidir.
FAQ2
Which component of Zephyr RTOS is affected by CVE-2026-12235?
This vulnerability involves the llext subsystem of Zephyr RTOS, specifically due to improper handling of PLT/RELA relocation entries for Xtensa relocatable objects.
What is the interim security recommendation for CVE-2026-12235?
Users are advised to avoid loading untrusted Xtensa relocatable extensions until a security patch is applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.