Threadlinqs IntelligenceStart free

VulnerabilityCVE-2026-11811Published 2026-08-10

CVE-2026-11811 — zephyrproject zephyr

low

As of 2026-08-10, CVE-2026-11811 is a LOW-severity vulnerability in zephyrproject zephyr, CVSS v3.1 3.7. No Threadlinqs-tracked threat campaign has been attributed to CVE-2026-11811 as of 2026-08-10; the identifier is re-checked against the Threadlinqs threat corpus on every daily ingest.

CVSS v3.1
3.7/10Low
EPSS
—No EPSS score yet
CISA KEV
NoNot in the KEV catalog
Tracked threats
0None linked yet
Priority
1.9/10Threadlinqs triage score
Published
CVSS v3.1 3.7 (LOW) · Priority 1.9/10 · Published 2026-08-10

Last updated:

What is CVE-2026-11811?

The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when zsock_setsockopt() (DTLS) or zsock_connect() subsequently failed the gate was false and cleanup_connection() was never called. The open descriptor in the global ctx.sock was then overwritten by the next attempt, permanently leaking it from the socket / net_context pool until reboot. The failing setup path is reached every time the OTA client tries to contact the UpdateHub server and the connection cannot be established — driven automatically by the periodic autohandler() poll (and on demand via the updatehub_probe()/updatehub_update() API or the updatehub run shell command). The DTLS handshake/connect outcome is influenceable by a network or on-path attacker who drops, resets, or otherwise disrupts traffic to the server, and also fails naturally whenever the server is unreachable. Each failed attempt permanently leaks one descriptor; once the shared socket pool is exhausted, networking degrades device-wide until the device is rebooted, a denial-of-service condition. Severity is low because the leak rate is bounded by the configured OTA poll interval (default once per 24 hours), the effect is gradual and recovered by reboot, and only builds with the UpdateHub client enabled are affected. There is no memory-corruption, information-disclosure, or authentication impact.

The record classifies CVE-2026-11811 under weakness class CWE-772. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 56 days ago.

Severity and exploitation probability

CVSS v3.1 base score
3.7 — LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA KEV
Not listed in the CISA Known Exploited Vulnerabilities catalog
Threadlinqs priority
1.9/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
Published
2026-08-10

Is CVE-2026-11811 being exploited?

It currently carries a trending score of 30 in the Threadlinqs vulnerability feed.

Affected products and versions

How to fix CVE-2026-11811

No vendor patch reference has been recorded for CVE-2026-11811 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.

Threat activity tracking CVE-2026-11811

No threat campaign in the Threadlinqs corpus currently references CVE-2026-11811, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.

Sources

Enriched from CVE.org, NVD. Last verified by Threadlinqs on . This product uses the NVD API but is not endorsed or certified by the NVD.

Vendor advisory and patch

Other references