PT-2026-95408 · Zephyr · Zephyr Rtos
CVE-2026-16512
·
Published
2026-09-18
·
Updated
2026-09-18
CVSS v3.1
3.1
Low
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A flaw exists in the
gptp handle msg() function within subsys/net/l2/ethernet/gptp/gptp.c where the gPTP header returned by GPTP HDR() is dereferenced and switched on hdr->message type without verifying that the received frame contains at least 34 bytes of payload. Because the gptp get hdr() accessor does not fail for short buffers, a truncated frame can result in a header pointer that accesses memory beyond the received data. Subsequent checks via GPTP VALID LEN() and GPTP CHECK LEN() fail to reject truncated SYNC, FOLLOWUP, PDELAY RESP, or SIGNALING messages.An unauthenticated peer on the same link can trigger this by sending an Ethernet frame with ethertype 0x88F7 to the PTP multicast address on an interface configured as a gPTP port with
CONFIG NET GPTP enabled. This typically requires a link capable of delivering sub-minimum frames, such as the native sim TAP driver or a MAC configured to accept undersized frames.The short packet is processed by state machines in
subsys/net/l2/ethernet/gptp/gptp md.c and subsys/net/l2/ethernet/gptp/gptp mi.c, which may read and copy data (such as the announce priority vector and hdr->port id) into state that is later transmitted. Depending on the allocator used, this results in either the disclosure of stale recycled buffer contents (with CONFIG NET BUF FIXED DATA SIZE) or genuine out-of-bounds reads (with CONFIG NET BUF VARIABLE DATA SIZE).Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zephyr Rtos