A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition between the request dispatch thread and the session cleanup thread when accessing shared session list nodes without proper synchronization.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Null Pointer Dereference in ccoap Session Management |
Mon, 31 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 27 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Null Pointer Dereference in ccoap Session Management | |
| Weaknesses | CWE-362 CWE-476 |
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition between the request dispatch thread and the session cleanup thread when accessing shared session list nodes without proper synchronization. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-27T00:00:00.000Z
Updated: 2026-08-31T17:35:30.112Z
Reserved: 2026-02-16T00:00:00.000Z
Link: CVE-2026-26456
Updated: 2026-08-31T17:35:22.581Z
Status : Deferred
Published: 2026-08-27T17:17:48.147
Modified: 2026-09-08T19:42:20.313
Link: CVE-2026-26456
No data.