PT-2026-95409 · Zephyr · Zephyr

CVE-2026-16514

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An out-of-bounds read exists in the gptp mi qualify announce() function within subsys/net/l2/ethernet/gptp/gptp mi.c. The issue occurs when processing the Path Trace TLV of a received IEEE 802.1AS Announce message. The system uses the attacker-controlled steps removed field to determine the loop bound instead of the tlv.len field, which indicates the actual number of identities carried. Consequently, the memcmp() function can access memory beyond the end of the received network buffer.
An unauthenticated attacker with layer-2 adjacency can trigger this by sending a specially crafted Announce frame with tlv.len set to 0 and steps removed set to 254. This causes the system to read approximately 2 KB of memory beyond the buffer. While this does not lead to information disclosure, it can cause the networking RX thread to fault if it accesses unmapped or MPU-protected memory, resulting in a denial of service. This issue affects builds with the experimental CONFIG NET GPTP enabled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16514
GHSA-MGXG-89RR-6855

Affected Products

Zephyr