Skip to content
EXPLOIT
.CC
CVEs
Search
About
synced 13 MIN AGO
T-13M
01
Record
STATE: —
02
Description
SRC: CNA
03
Metadata
SCHEMA: CVE JSON 5
04
Affected products
PAIRS: —
05
References
REFS: —
01
Record
STATE: PUBLISHED
CVE-2026-12366
Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal
High
PUBLISHED
CNA: zephyr
Base score
8.8
CVSS v3.x
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
View raw JSON
CVE Program record
02
Description
CNA: zephyr
Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal
03
Metadata
SCHEMA: 5.2
Published
2026-08-14 17:52Z
2 HR AGO
Last updated
2026-08-14 19:21Z
1 HR AGO
Reserved
2026-06-16
Assigning CNA
zephyr
Record state
PUBLISHED
Severity
High (CVSS 8.8)
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-416
SSVC decision
Exploitation
none
Automatable
no
Technical Impact
total
Data version
5.2
Document digest
f2095b189078f38b5375c8fb1ad95f404e65817fc8340b66182c91e9f4a287d0
04
Affected products
PAIRS: 1
Vendor
Product
Versions
Platforms
zephyrproject
zephyr
1.12.0 to < 4.5.0
—
05
References
REFS: 2
github.com
Fix commit
https://github.com/zephyrproject-rtos/zephyr/commit/1e68351a2572f9ae480be71da4aca9aa90db3fb2
patch
github.com
GHSA-x96g-542c-gccq
https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-x96g-542c-gccq