---
id: CVE-2026-18417
title: >-
  The native BSD-socket layer recorded a pending asynchronous socket error by
  type-punning it into struct net_context's void user_data field (ctx->user_data
  = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(),
  zsock_conne…
summary: >-
  The native BSD-socket layer recorded a pending asynchronous socket error by
  type-punning it into struct net_context's void user_data field (ctx->user_data
  = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(),
  zsock_conne…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-843
vendor: zephyrproject
product: zephyr
affected:
  - zephyr >= 4.3.0 < 4.4.2
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T00:17:04.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18417'
references:
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/commit/ef370a57d07637aaee8cec7b0bcebf4002ac8f54
    label: vulnerabilities@zephyrproject.org
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p8r8-8mw8-3wf9
    label: vulnerabilities@zephyrproject.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T00:24:04.805Z'
---

## Overview

The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_connected_cb() and zsock_close_ctx() in subsys/net/lib/sockets/sockets_inet.c), reading it back with POINTER_TO_INT(). That same field is owned by the network stack for listening TCP contexts: net_tcp_accept() stores the parent context pointer there and the TCP core passes it back to the registered accept callback. A failed accept therefore left a small integer (an errno value) where the stack expected a struct net_context .

When the network interface carrying a listening TCP socket goes down, close_tcp_conn() in subsys/net/ip/tcp.c invokes the accept callback with -ENETDOWN and the context's user_data. In v4.3.0 the callback was not disarmed afterwards, so a second interface-down event forwarded the previously stored errno to zsock_accepted_cb(), which dereferenced it as the parent context and performed several stores through it (sock_set_error()'s read-modify-write of socket_data, k_fifo_cancel_wait(&parent->recv_q)) — the crash described in the fix's commit message. v4.3.1 and v4.4.x carry a later change clearing conn->accept_cb after the error callback (269cb8823d3 on the v4.3 branch, 913fae5169425550f2364655298fceb79b320066 on main), which closes that repeat path; on those releases the poisoned cookie remains reachable only by a narrower race, a handshake completing alongside the interface-down still passing the stale cookie to k_fifo_put(&parent->accept_q, ...), and by getsockopt(SO_ERROR), which reads the field back unconditionally.

On v4.3.0 an application that keeps a listening TCP socket open across repeated link-down events is sufficient to reach the defect; the triggering condition is a network-interface state change, not attacker-supplied packet data, so the practical attacker is one able to force the link down repeatedly (for example an adjacent attacker disrupting a wireless link) or one with local/physical access. Because both the faulting address and the stored data are fixed small constants derived from the errno value, the outcome is a wild-pointer access leading to a kernel fatal error — a denial of service (device crash or reset) rather than an attacker-directed memory corruption.

The fix stores the pending error in a dedicated net_context.sock_error field and converts every producer and consumer to sock_set_error()/sock_get_error(), leaving user_data untouched. As a side effect it also stops getsockopt(SO_ERROR) — which is evaluated unconditionally — from returning the kernel address held in user_data to a userspace application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
