What is CVE-2026-12631?
CVE-2026-12631 identifies a flaw in the Zephyr kernel's validation logic for `k_thread_join()` and `k_thread_abort()` system calls. The `thread_obj_validate()` function's default switch case incorrectly denies access, potentially allowing privilege bypass. Affected Zephyr-based systems should apply vendor patches.
Azərbaycanca: CVE-2026-12631 Zephyr ƏS kernelində `k_thread_join()` və `k_thread_abort()` sistem çağırışlarında validasiya məntiqində səhv aşkarlayıb. `thread_obj_validate()` funksiyası defolt olaraq girişi rədd edən `switch` budağı icra edir, bu da imtiyazlı əməliyyatların yan keçilməsinə səbəb ola bilər. Zərərçəkən sistemlər Zephyr-in təsirlənən versiyasını istifadə edən IoT və gömülü cihazlardır; istehsalçıdan yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ1
Which operations in Zephyr OS can be bypassed due to CVE-2026-12631?
CVE-2026-12631 can cause a bypass of privileged operations in the `k_thread_join()` and `k_thread_abort()` system calls within the Zephyr kernel.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.