
# CVE-2026-10643 #Zephyr RTOS recvmsg() Heap Out-of-Bounds Write Exploit Kit - **Affected**: Zephyr v3.6.0 – v4.4.0 - **Component**: `subsys/net/lib/sockets/sockets_inet.c` (`insert_pktinfo()`) - **Impact**: Kernel heap memory corruption, exploitable from unprivileged threads under `CONFIG_USERSPACE` - **Requirements**: `IP_PKTINFO` / `IPV6_RECVPKTINFO` enabled, UDP socket, `recvmsg()` with undersized control buffer #0days #exploit #CVE #cybersecurity #hacking #security #antisec #infosec
Post summary
The text discloses a heap out‑of‑bounds write in Zephyr RTOS (CVE‑2026‑10643), listing affected versions, impact, and conditions, and notes an exploit kit without providing exploit code or a patch.


