PT-2026-95410 · Zephyr · Zephyr

CVE-2026-16515

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

4.7

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Zephyr (affected versions not specified)
Description The net icmpv6 send error() function in subsys/net/ip/icmpv6.c fails to implement all RFC 4443 section 2.4 suppression rules, which dictate that an ICMPv6 error should not be answered with another ICMPv6 error. Specifically, it does not verify if the triggering packet's source address identifies a single node or if the packet was sent to a multicast destination. This flaw affects the extension-header, unknown-next-header, and fragmentation paths in subsys/net/ip/ipv6.c and subsys/net/ip/ipv6 fragment.c.
An unauthenticated attacker on the same link can exploit this to cause a reflection attack by sending an IPv6 packet to the link-local all-nodes group ff02::1 with a spoofed source address, forcing all nodes to send ICMPv6 Parameter Problem messages to the victim. Alternatively, sending a unicast packet with a multicast source address can cause the node to flood the link with multicast frames. This results in degraded availability of the shared link and the reflection victim, particularly on constrained mesh links like 802.15.4/Thread.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16515
GHSA-V5VW-M78M-H46G

Affected Products

Zephyr