Zephyr · Zephyr · CVE-2026-13351
**Name of the Vulnerable Software and Affected Versions**
Zephyr (affected versions not specified)
**Description**
An issue in the IPv6 network stack allows a denial of service by sending a small number of maliciously fragmented IPv6 packets. When the fragment-header processing path handles these packets, the associated RX network packet buffer, which is allocated from a memory slab, is not released back to the pool. This leads to the exhaustion of all RX buffer slots, preventing the device from obtaining new buffers and stopping all incoming traffic.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.