A new vulnerability in the Infineon AIROC Wi-Fi driver can cause permanent loss of connectivity on Zephyr-based devices. CVE-2026-12999 does not allow data theft or code execution, but a near-end attacker could cause the wireless subsystem to cause a denial of service.

The vulnerability was reported in NVD on August 22, 2026 and concerns the handling of temporary failures when sending packets. The SecNews technical team evaluated the available evidence and notes that the issue mainly concerns embedded implementations and not common home routers.
Zephyr is a real-time operating system used in small and medium-sized embedded devices. The Infineon AIROC Wi-Fi driver may be present in products with different hardware and different configurations, so the presence of the driver does not by itself mean that every device is exposed in the same way.
See also: Multicluster Engine: Critical vulnerability CVE-2026-73267
How the Infineon AIROC Wi-Fi vulnerability works
The problem lies in the airoc_mgmt_send() in the file drivers/wifi/infineon/airoc_wifi.c. For each outgoing packet, the driver allocates a net_buf from a small, fixed-size memory pool called airoc_pool.
When the WHD library returned a synchronous failure, the previous version of the driver would exit with a -EIO without releasing the object. Thus, each failed send left another buffer bound, even though it was no longer in use.

The pool is shared between the send and receive functions and, with default settings, contains only 20 buffers: ten for transmit and ten for receive. When it is exhausted, subsequent requests fail and the device cannot continue wireless communication normally.
What CVE-2026-12999 means for devices
The Zephyr advisory rates the vulnerability as moderate severity, with a CVSS score of 7.0 for availability in model 3.1. The attack requires presence in wireless range and high sophistication, and no account or user action is required.
One possible scenario is a station repeatedly disconnecting or disassociating while the device continues to attempt transmissions. This is not remote code execution or a leak of personal data. The result is a denial of service: the Wi-Fi connection is lost and, according to Zephyr, a reboot is required to restore it.
The same effect can occur gradually from common transient failures, without targeted action. The likelihood depends on the application, the hardware, and how it handles reconnections. Therefore, manufacturers of embedded products should check whether they use the affected subsystem.
In a practical investigation, engineers should check Zephyr versions in the device software, driver configuration, and logs for repeated send failures. Loss of Wi-Fi after a series of disconnections is not evidence of an attack, but it is an indication worth investigating.
See also: Hackers exploit critical RCE vulnerability in Microsoft Entra ID

The fix and developers' actions
The vulnerability affects Zephyr versions 3.6.0 through 4.4.2, according to the project entry. The patched version is 4.4.2, and the change has been pushed to some maintenance branches. Teams maintaining their own branches should apply the corresponding backport.
The corrective change to the source code calls airoc_wifi_buffer_release() when the send fails synchronously, returning the buffer to the pool. It also removes a double semaphore signaling call during disconnection, which had no security impact on its own.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Product managers are urged to upgrade Zephyr to 4.4.2 or apply the official fix, review any local code migrations, and test connection loss scenarios. A simple reboot temporarily restores an affected device, but does not address the cause.
On systems that cannot be upgraded immediately, the development team should limit wireless exposure and monitor for transmission failures. These measures reduce the risk, but are not a substitute for installing version 4.4.2 or the official backport.
See also: Citrix NetScaler: Critical Authentication Bypass Vulnerability

CVE-2026-12999 is a reminder that a driver-level memory management flaw can impact the entire availability of a device. While the exploit is not simple and is limited to a nearby wireless environment, timely upgrading remains the safest option for those using Infineon AIROC Wi-Fi inside Zephyr products.
