中的 函数基于 计算随机化的邻居发现(ND)可达时间。其计算公式为: 其中, , ,均使用整数除法。 当 为 1 时, (即 1/2 = 0)和模数 (即 3*1/2 - 0 = 1)同时“坍缩”,导致函数返回 0。随后, 将该 0 值存入 。 受攻击者控制: 中的 会接受来自路由器通告(Router Advertisement, RA)的可达时间字段,只要该字段非零且不超过 。因此,一条未认证、仅需链路本地邻接关系的 RA,若携带可达时间为 1,即可使计算出的可达时间变为 0。默认情况下,路由器通告是未认证的,且
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 1.7.0< 4.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 1.7.0 ~ 4.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16147 | 6.8 MEDIUM | it82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-f |
| CVE-2026-15924 | 5.9 MEDIUM | Use-after-free / double-free from unsynchronized concurrent access to the TLS client sessi |
| CVE-2026-15923 | 4.6 MEDIUM | Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk_ |
| CVE-2026-16148 | 4.6 MEDIUM | Kernel panic in the it82xx2 USB device controller driver via re-initialization of a busy d |
No comments yet