PT-2026-78685 · Git+1 · Zephyr

CVE-2026-12633

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The IPv6 neighbor-discovery code in subsys/net/ip/ipv6 nbr.c fails to properly bound the 8-bit context len field when processing the 6LoWPAN Context Option (6CO) within ICMPv6 Router Advertisements. In the handle ra 6co() function, if context len is between 136 and 255, a calculation for the memset() function underflows the unsigned size t argument. This results in an unbounded out-of-bounds memory write that zeroes kernel memory beyond the 6lo context structure. This issue is reachable by an unauthenticated attacker on the same local link who can send a crafted Router Advertisement. The flaw is present when CONFIG NET 6LO CONTEXT is enabled and can lead to a remote denial of service and memory integrity loss.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12633
GHSA-H5M5-HM6J-CGPF

Affected Products

Zephyr