
CVE-2026-10648 mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of smp_packet_alloc() before checking it for NULL. … https://www.cve.org/CVERecord?id=CVE-2026-10648
Post summary
The text provides a concise disclosure of CVE-2026-10648, describing the vulnerable function and omission of null checks, but contains no mention of PoC, exploit tool, active exploitation, or patch.


