PT-2026-52488 · Zephyr · Zephyr

·

CVE-2026-13351

·

Published

2026-06-25

·

Updated

2026-07-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zephyr (affected versions not specified)
Description An issue in the IPv6 network stack allows a denial of service by sending a small number of maliciously fragmented IPv6 packets. When the fragment-header processing path handles these packets, the associated RX network packet buffer, which is allocated from a memory slab, is not released back to the pool. This leads to the exhaustion of all RX buffer slots, preventing the device from obtaining new buffers and stopping all incoming traffic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13351
GHSA-CV4Q-2J56-4WQF

Affected Products

Zephyr