CVE-2026-10681 - SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot
Summary
This entry details a vulnerability found in the target system. The exploit was published on 2026-08-03 and has garnered 11 views from the community. It is classified under the local category. Users are advised to review the source code in the Detail tab for technical specifics.
Zafiyet Ozet Bilgileri
Zafiyet Detayı (Turkce)
Zephyr'in kullanıcı alanı dinamik nesneleri alt sisteminde, kernel/userspace/userspace.c'deki thread_idx_alloc(), list_lock'u tutmadan global _thread_idx_map[] bit eşleminden yeni bir iş parçacığı izin indeksi tahsis etti. SMP sistemlerinde, k_object_alloc(K_OBJ_THREAD) sistem çağrısını eşzamanlı olarak çağıran iki kullanıcı modu iş parçacığının her ikisi de aynı düşük serbest biti gözlemleyebilir, onu temizlemek için aynı atomik olmayan RMW'yi gerçekleştirebilir ve…
Orijinal Aciklama (Ingilizce)
CVE ID, Product, Vendor ... Pricing Browse by Apps View All Apps Splunk Slack Webhook Teams Jira Chrome API