目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-18415— IEEE 802.15.4 L2发送路径越界写入漏洞

一分钟漏洞结论

影响对象
zephyrproject zephyr
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

这段描述涉及 Zephyr RTOS(或类似嵌入式操作系统)中 IEEE 802.15.4 网络协议栈的一个安全漏洞。以下是该漏洞描述信息的中文翻译: *** 中的 函数会将待发送的数据包拷贝到一个固定的 125 字节传输缓冲区( ,大小定义为 )中。在启用了 配置(当设置 时,此为默认配置)的构建版本中,当不需要进行 6LoWPAN 分片时,程序执行了未检查边界的数据拷贝操作 。唯一的防护机制是 内部的 ,但该断言在未启用 时会被编译掉,导致 oversized(过大)的数据包会静默地溢出该帧缓冲区。 该缺陷无法

CVSS 6.3 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-18415 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames
来源: CVE Program / CVE List V5
Vulnerability Description
ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with CONFIG_NET_L2_IEEE802154_FRAGMENT enabled (the default whenever CONFIG_NET_6LO is set), the branch taken when 6LoWPAN fragmentation is not required performed an unchecked net_buf_add_mem(frame_buf, pkt_buf->data, pkt_buf->len). The only guard was __ASSERT_NO_MSG() inside net_buf_simple_add(), which is compiled out without CONFIG_ASSERT, so an oversized packet silently overran the frame buffer. The defect is not reachable from the radio: for NET_AF_INET6 packets ieee802154_6lo_encode_pkt() compares the whole packet length against IEEE802154_MTU and takes the fragmentation path when it does not fit, so every buffer copied on the unfragmented branch is within bounds. It is reachable through NET_AF_PACKET sockets bound to an 802.15.4 interface: for NET_SOCK_RAW the 6LoWPAN block is skipped entirely and for NET_SOCK_DGRAM it returns early on the address-family test, leaving no length validation anywhere on the transmit path (net_context_sendto() and net_if_tx() apply none, and pkt_buffer_length() does not clamp the allocation for this L2). An application — or, in a CONFIG_USERSPACE build, an unprivileged application thread using the zsock_socket()/zsock_sendto() syscalls — can therefore drive a supervisor-mode out-of-bounds write of chosen bytes past the 125-byte pool buffer. With the default CONFIG_NET_BUF_FIXED_DATA_SIZE of 128 bytes the overrun is bounded to roughly ll_hdr_len + 3 bytes; with CONFIG_NET_BUF_VARIABLE_DATA_SIZE a single storage buffer can be as large as CONFIG_NET_PKT_BUF_TX_DATA_POOL_SIZE, making the overrun far larger. The consequence is corruption of memory adjacent to the pool, with a crash or further compromise of kernel state as the practical impact. The fix validates ll_hdr_len + net_pkt_get_len(pkt) + authtag_len against IEEE802154_MTU before any copy and adds a tailroom-checking copy_pkt_to_frame() helper that returns -EMSGSIZE instead of overrunning the buffer. The same change also linearizes the whole net_buf chain into one MAC frame, so packet storage boundaries no longer become frame boundaries on the wire.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
zephyrproject zephyr 3.2.0 ~ 4.4.2 -

二、漏洞 CVE-2026-18415 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-18415 的情报信息

请登录查看更多情报信息。

CVE-2026-18415 其他参考 (2)

同批安全公告 · zephyrproject · 2026-09-28 · 共 5 条

CVE-2026-16513 7.8 HIGH RTIO系统调用验证器漏洞允许任意内核写入
CVE-2026-18413 7.8 HIGH NXP MCUX LPADC ADC驱动越界写入漏洞
CVE-2026-18414 7.8 HIGH ADI MAX32 ADC驱动越界写入漏洞
CVE-2026-18416 3.7 LOW CoAP well-known-core 边界读取漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-18415

暂无评论


发表评论