PT-2026-102354 · Zephyr Os · Zephyr Os
CVE-2026-18415
·
Published
2026-09-28
·
Updated
2026-09-28
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zephyr OS (affected versions not specified)
Description
An out-of-bounds write can occur in the
ieee802154 send() function within subsys/net/l2/ieee802154/ieee802154.c. When CONFIG NET L2 IEEE802154 FRAGMENT is enabled and 6LoWPAN fragmentation is not required, the system performs an unchecked memory addition using net buf add mem(). This allows an oversized packet to overrun the 125-byte transmit buffer tx frame buf pool.While not reachable via radio for
NET AF INET6 packets, the issue is reachable through NET AF PACKET sockets bound to an 802.15.4 interface. Specifically, for NET SOCK RAW, the 6LoWPAN block is skipped, and for NET SOCK DGRAM, the process returns early on the address-family test, bypassing length validation. An application or an unprivileged thread in a CONFIG USERSPACE build using zsock socket() and zsock sendto() can trigger a supervisor-mode write past the pool buffer. The impact includes memory corruption adjacent to the pool, potentially leading to a system crash or compromise of the kernel state.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zephyr Os