A high-severity flaw tracked as CVE-2026-12366 was disclosed in the Zephyr RTOS, where userspace object disposal could free an armed, dynamically allocated k_timer without first cancelling its queued timeout. The bug leaves a dangling entry in the global timeout queue, and when the timer later expires, Zephyr may dereference freed kernel heap memory in kernel or ISR context, creating a deterministic use-after-free and memory-corruption condition.
The issue is reachable by an unprivileged user thread when CONFIG_USERSPACE and CONFIG_DYNAMIC_OBJECTS are enabled, making it a potential sandbox-escape and local privilege-escalation primitive. Zephyr addressed the problem in a kernel change that adds k_timer_cleanup(), which cancels the timer, waits for any in-flight expiration handler to finish, and can return -EAGAIN if threads are still pending on the timer wait queue; the fix also updates userspace cleanup logic and tracing hooks to use the safer timer cleanup path.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-12366 was published as a high-severity Zephyr use-after-free vulnerability affecting versions 1.12.0 through before 4.5.0. The issue allows an unprivileged user thread to trigger deterministic kernel-memory corruption via disposal of an armed dynamically allocated k_timer, creating a local privilege-escalation primitive.
A Zephyr kernel patch introduced the new k_timer_cleanup() API and updated userspace object cleanup to call it for K_OBJ_TIMER objects before freeing their storage. The change prevents freeing an armed dynamically allocated timer while its timeout or expiration handler could still reference the memory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.