Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18415— Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

这段描述涉及 Zephyr RTOS(或类似嵌入式操作系统)中 IEEE 802.15.4 网络协议栈的一个安全漏洞。以下是该漏洞描述信息的中文翻译: *** 中的 函数会将待发送的数据包拷贝到一个固定的 125 字节传输缓冲区( ,大小定义为 )中。在启用了 配置(当设置 时,此为默认配置)的构建版本中,当不需要进行 6LoWPAN 分片时,程序执行了未检查边界的数据拷贝操作 。唯一的防护机制是 内部的 ,但该断言在未启用 时会被编译掉,导致 oversized(过大)的数据包会静默地溢出该帧缓冲区。 该缺陷无法

CVSS 6.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18415

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames
Source: CVE Program / CVE List V5
Vulnerability Description
ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with CONFIG_NET_L2_IEEE802154_FRAGMENT enabled (the default whenever CONFIG_NET_6LO is set), the branch taken when 6LoWPAN fragmentation is not required performed an unchecked net_buf_add_mem(frame_buf, pkt_buf->data, pkt_buf->len). The only guard was __ASSERT_NO_MSG() inside net_buf_simple_add(), which is compiled out without CONFIG_ASSERT, so an oversized packet silently overran the frame buffer. The defect is not reachable from the radio: for NET_AF_INET6 packets ieee802154_6lo_encode_pkt() compares the whole packet length against IEEE802154_MTU and takes the fragmentation path when it does not fit, so every buffer copied on the unfragmented branch is within bounds. It is reachable through NET_AF_PACKET sockets bound to an 802.15.4 interface: for NET_SOCK_RAW the 6LoWPAN block is skipped entirely and for NET_SOCK_DGRAM it returns early on the address-family test, leaving no length validation anywhere on the transmit path (net_context_sendto() and net_if_tx() apply none, and pkt_buffer_length() does not clamp the allocation for this L2). An application — or, in a CONFIG_USERSPACE build, an unprivileged application thread using the zsock_socket()/zsock_sendto() syscalls — can therefore drive a supervisor-mode out-of-bounds write of chosen bytes past the 125-byte pool buffer. With the default CONFIG_NET_BUF_FIXED_DATA_SIZE of 128 bytes the overrun is bounded to roughly ll_hdr_len + 3 bytes; with CONFIG_NET_BUF_VARIABLE_DATA_SIZE a single storage buffer can be as large as CONFIG_NET_PKT_BUF_TX_DATA_POOL_SIZE, making the overrun far larger. The consequence is corruption of memory adjacent to the pool, with a crash or further compromise of kernel state as the practical impact. The fix validates ll_hdr_len + net_pkt_get_len(pkt) + authtag_len against IEEE802154_MTU before any copy and adds a tailroom-checking copy_pkt_to_frame() helper that returns -EMSGSIZE instead of overrunning the buffer. The same change also linearizes the whole net_buf chain into one MAC frame, so packet storage boundaries no longer become frame boundaries on the wire.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 3.2.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-18415

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18415

请登录查看更多情报信息。

Other References for CVE-2026-18415 (2)

Same Patch Batch · zephyrproject · 2026-09-28 · 5 CVEs total

CVE-2026-16513 7.8 HIGH Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allo
CVE-2026-18413 7.8 HIGH Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer si
CVE-2026-18414 7.8 HIGH Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size
CVE-2026-18416 3.7 LOW Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_path_uri)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18415

No comments yet


Leave a comment