PT-2026-102354 · Zephyr Os · Zephyr Os

CVE-2026-18415

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zephyr OS (affected versions not specified)
Description An out-of-bounds write can occur in the ieee802154 send() function within subsys/net/l2/ieee802154/ieee802154.c. When CONFIG NET L2 IEEE802154 FRAGMENT is enabled and 6LoWPAN fragmentation is not required, the system performs an unchecked memory addition using net buf add mem(). This allows an oversized packet to overrun the 125-byte transmit buffer tx frame buf pool.
While not reachable via radio for NET AF INET6 packets, the issue is reachable through NET AF PACKET sockets bound to an 802.15.4 interface. Specifically, for NET SOCK RAW, the 6LoWPAN block is skipped, and for NET SOCK DGRAM, the process returns early on the address-family test, bypassing length validation. An application or an unprivileged thread in a CONFIG USERSPACE build using zsock socket() and zsock sendto() can trigger a supervisor-mode write past the pool buffer. The impact includes memory corruption adjacent to the pool, potentially leading to a system crash or compromise of the kernel state.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18415
GHSA-J76J-JRJC-XGVP

Affected Products

Zephyr Os