PT-2026-82107 · Git+1 · Zephyr

CVE-2026-13481

·

Published

2026-08-26

·

Updated

2026-08-31

CVSS v3.1

5.4

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP MGMT TIME management id. In the tlv mgmt post recv() function, the PTP MGMT TIME case casts mgmt tlv->data to a 10-byte struct ptp timestamp and performs read and write operations without verifying that the TLV data field meets the minimum required size. An adjacent attacker on the local PTP segment can send a PTP MSG MANAGEMENT message with a short PTP MGMT TIME TLV, leading to an out-of-bounds read of adjacent in-object memory and bounded in-place corruption of the parsed timestamp. This issue results in minor information exposure and corruption of the device's parsed management TIME value.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13481
GHSA-MH5R-JXH8-HXWX

Affected Products

Zephyr