A vulnerability classified as problematic was found in Zephyr Project Zephyr up to 4.4.1. This issue affects the function usbd_cdc_ncm_cth of the file subsys/usb/device_next/class/usbd_cdc_ncm.c of the component CDC NCM Class Handler. The manipulation of the argument wLength results in out-of-bounds write.

This vulnerability is identified as CVE-2026-12052. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.