A vulnerability, which was classified as problematic, was found in Zephyr Project Zephyr up to 4.4.1. The affected element is the function llext_link_plt of the file subsys/llext/llext_link.c of the component Linkable Loadable Extensions. Such manipulation of the argument r_offset leads to out-of-bounds write.

This vulnerability is uniquely identified as CVE-2026-12235. Local access is required to approach this attack. No exploit exists.

You should upgrade the affected component.