Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16512— Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

中的 函数在通过 获取 gPTP 头部后,直接解引用该头部并根据 进行分支处理,但之前并未检查接收到的帧是否至少包含 (即 34)字节的负载。 头部访问器函数 特意设计为对于短缓冲区永远不返回错误——它直接返回 ,并将验证工作留给调用者。因此,一个被截断的帧会生成一个指向超出实际接收数据范围的内存区域的头部指针。 后续针对每种消息类型的检查无法弥补这一缺陷:在剥离以太网头部之后, 简化为 。由于所有固定大小的 gPTP 消息都不满足此条件,因此 永远不会拒绝被截断的 SYNC、FOLLOW_UP、PDELAY_RE

CVSS 3.1 · Low EPSS 0.17% · P7

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
zephyrproject zephyr 1.13.0< 4.4.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-16512

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames
Source: CVE Program / CVE List V5
Vulnerability Description
gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) bytes of payload. The header accessor gptp_get_hdr() deliberately never fails for a short buffer — it returns pkt->frags->data and leaves validation to its callers — so a truncated frame produced a header pointer covering memory beyond the received data. The per-message-type checks that follow do not compensate: GPTP_VALID_LEN() reduces to len > 60 once the Ethernet header has been pulled, which is false for every fixed-size gPTP message, so GPTP_CHECK_LEN() never rejects a truncated SYNC, FOLLOWUP, PDELAY_RESP or SIGNALING message. The defect is reached by an unauthenticated peer on the same link sending an Ethernet frame with ethertype 0x88F7 to the PTP multicast address on an interface configured as a gPTP port, with CONFIG_NET_GPTP enabled. Because conformant Ethernet pads frames to 60 bytes, a payload shorter than 34 bytes generally requires a link that can deliver sub-minimum frames — for example the native_sim TAP driver (drivers/ethernet/eth_native_tap.c), which forwards whatever length the host device supplies, or a MAC configured to accept undersized frames. The short packet is retained (net_pkt_ref() into rcvd_sync_ptr, rcvd_follow_up_ptr, rcvd_pdelay_resp_ptr or rcvd_announce_ptr) and later parsed by the media-dependent and media-independent state machines in subsys/net/l2/ethernet/gptp/gptp_md.c and subsys/net/l2/ethernet/gptp/gptp_mi.c, which read tens of further bytes and copy some of them (the announce priority vector, hdr->port_id) into state that is subsequently transmitted. Under the default fixed-size buffer allocator (CONFIG_NET_BUF_FIXED_DATA_SIZE, 128-byte fragments) the accesses stay inside the allocated fragment and disclose stale recycled buffer contents; under the experimental CONFIG_NET_BUF_VARIABLE_DATA_SIZE allocator, where fragments are heap-allocated at the exact frame length, they are genuine out-of-bounds reads. There is no write and no availability impact.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 1.13.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-16512

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16512

登录查看更多情报信息。

Patches & Fixes for CVE-2026-16512 (1)

Vendor Advisories for CVE-2026-16512 (1)

Same Patch Batch · zephyrproject · 2026-09-18 · 3 CVEs total

CVE-2026-16515 4.7 MEDIUM ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses
CVE-2026-16514 4.3 MEDIUM Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved

IV. Related Vulnerabilities

V. Comments for CVE-2026-16512

No comments yet


Leave a comment