HB
One Byte Short of Null: CVE-2026-10672 — Out-of-Bounds Read in Zephyr's LwM2M Firmware Update Client
A 200-byte Package URI, a 128-byte buffer, and an memcpy that copies exactly the destination size — the recipe for a silent memory leak out of a few hundred million IoT devices. No NUL terminator, no crash, no obvious overflow. Just a slow bleed of function pointers and DTLS sec…