PT-2026-82107 · Git+1 · Zephyr
CVE-2026-13481
·
Published
2026-08-26
·
Updated
2026-08-31
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
The IEEE 1588 PTP management-message parser in
subsys/net/lib/ptp/tlv.c mishandles the PTP MGMT TIME management id. In the tlv mgmt post recv() function, the PTP MGMT TIME case casts mgmt tlv->data to a 10-byte struct ptp timestamp and performs read and write operations without verifying that the TLV data field meets the minimum required size. An adjacent attacker on the local PTP segment can send a PTP MSG MANAGEMENT message with a short PTP MGMT TIME TLV, leading to an out-of-bounds read of adjacent in-object memory and bounded in-place corruption of the parsed timestamp. This issue results in minor information exposure and corruption of the device's parsed management TIME value.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zephyr