zephyrproject-rtos.zephyr is vulnerable to Denial of Service (DoS)
37
Low Risk
The UpdateHub over-the-air client leaks its CoAP/DTLS socket descriptor on connection-setup failure paths because the cleanup step is gated on a flag that is already cleared when the socket is opened. When the DTLS option or the connect step fails, the descriptor is never closed and is overwritten by the next attempt, permanently leaking it from the shared socket pool. The failing path runs on every periodic OTA poll when the server is unreachable or when traffic is disrupted, so repeated failures gradually exhaust the pool and degrade device networking until reboot. The fix closes the open socket on the failure paths.
You are affected if you are using a version that falls within the vulnerable range and you enable the UpdateHub OTA client, whose periodic polling reaches the leaking connection-setup path when the server is unreachable.
zephyrproject-rtos.zephyr is vulnerable to Denial of Service (DoS) in versions 2.0.0 - 4.4.1.
Upgrade the zephyrproject-rtos.zephyr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant