Threadlinqs IntelligenceStart free

VulnerabilityCVE-2026-10667Published 2026-07-12

CVE-2026-10667 — zephyrproject zephyr

high

As of 2026-07-13, CVE-2026-10667 is a HIGH-severity vulnerability in zephyrproject zephyr, CVSS v3.1 7.8, EPSS 0.1% (1.1th percentile). No Threadlinqs-tracked threat campaign has been attributed to CVE-2026-10667 as of 2026-07-13; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

CVSS v3.1
7.8/10High
EPSS
0.1%Higher than 1.1% of scored CVEs
CISA KEV
NoNot in the KEV catalog
Tracked threats
0None linked yet
Priority
3.9/10Threadlinqs triage score
Published
Updated 2026-07-13
CVSS v3.1 7.8 (HIGH) · EPSS 0.1% (higher than 1.1% of all scored CVEs) · Priority 3.9/10 · Published 2026-07-12

Last updated:

What is CVE-2026-10667?

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. Iteration over this list in k_object_wordlist_foreach() was performed under lists_lock using the SAFE iterator (which caches the next node), but list removal and freeing of nodes was performed under different, disjoint spinlocks: objfree_lock in k_object_free() and obj_lock in unref_check(). On an SMP system, while one CPU iterated obj_list under lists_lock, another CPU could unlink and k_free() the dyn_obj node that the iterator had cached as its next pointer, causing the iterator to dereference freed kernel memory (use-after-free / dangling list traversal). All of the racing operations are reachable from unprivileged user-mode threads via system calls: k_object_alloc/k_object_alloc_size and k_object_release drive removals through unref_check() (under obj_lock), while k_thread_abort and thread creation drive the iteration through k_thread_perms_all_clear()/k_thread_perms_inherit() (under lists_lock). A deprivileged user thread on a CONFIG_SMP + CONFIG_USERSPACE build can therefore corrupt the kernel's object-tracking structures across the userspace security boundary, yielding kernel memory corruption (potential privilege escalation) or a kernel crash (denial of service). The fix removes objfree_lock and serializes every obj_list modification under lists_lock, including holding it across find+remove in k_object_free() and around unref_check() in k_thread_perms_clear(). Affects CONFIG_SMP+CONFIG_USERSPACE+CONFIG_DYNAMIC_OBJECTS configurations; the defect dates to the 2019 spinlockification (commit 8a3d57b6cc6, first released in v1.14.0) and shipped through v4.4.0.

The record classifies CVE-2026-10667 under weakness class CWE-416. Its CVSS v3 base vector states that the flaw requires local access to the host, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 85 days ago.

Severity and exploitation probability

CVSS v3.1 base score
7.8 — HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS (FIRST)
0.1% probability of exploitation in the next 30 days, higher than 1.1% of all scored CVEs
CISA KEV
Not listed in the CISA Known Exploited Vulnerabilities catalog
Threadlinqs priority
3.9/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
Published
2026-07-12, last modified 2026-07-13

Is CVE-2026-10667 being exploited?

It currently carries a trending score of 30 in the Threadlinqs vulnerability feed.

Affected products and versions

How to fix CVE-2026-10667

No vendor patch reference has been recorded for CVE-2026-10667 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

Threat activity tracking CVE-2026-10667

No threat campaign in the Threadlinqs corpus currently references CVE-2026-10667, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

Sources

Enriched from CVE.org, NVD, FIRST EPSS. Last verified by Threadlinqs on . This product uses the NVD API but is not endorsed or certified by the NVD.

Vendor advisory and patch

Other references