What is CVE-2026-8718?
CVE-2026-8718 is a buffer size validation flaw in the sockets_tls.c file of the Zephyr real-time operating system. The getsockopt call passes a user-supplied optval buffer directly to mbedtls_ssl_get_peer_cid() without ensuring it meets the minimum required size, potentially leading to memory corruption. Affected Zephyr-based systems should apply the security patch promptly.
Azərbaycanca: CVE-2026-8718, Zephyr real-time əməliyyat sisteminin sockets_tls.c faylında aşkar edilmiş bufer ölçüsünün yoxlanılmaması zəifliyidir. getsockopt çağırışı zamanı istifadəçi tərəfindən təqdim olunan optval buferi mbedtls_ssl_get_peer_cid() funksiyasına birbaşa ötürülür ki, bu da yaddaş pozuntusuna səbəb ola bilər. Zephyr istifadə edən sistemlərdə təhlükəsizlik yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which file of the Zephyr operating system was the CVE-2026-8718 vulnerability discovered?
CVE-2026-8718 was discovered in the sockets_tls.c file of the Zephyr real-time operating system.
What outcome can an attacker cause by exploiting CVE-2026-8718?
Exploiting CVE-2026-8718 can lead to memory corruption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.