Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19186— Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds read and write

Quick assessment

Affected
zephyrproject zephyr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是对该漏洞描述信息的中文翻译: 中的函数 在计算有效载荷长度时,使用了公式 ,但在此之前并未检查接收到的帧长度是否至少为 字节。由于这三个变量均为 类型,如果某个帧的有效载荷长度小于配置的认证标签长度,减法操作将会发生下溢(wrap around),导致结果变为一个较大的值(最大为 255)。 这个下溢后的长度被原封不动地传递给 ,并作为 / 传入 CCM(CBC-MAC with Ciphertext)加密操作中,同时 指向 。由于接收缓冲区是根据从无线电驱动程序接收到的帧的实际长度精确分配的,因此加密层会在

CVSS 8.1 · High

Possible ATT&CK Techniques 1 AI

T1498 · Network Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19186

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Integer underflow in IEEE 802.15.4 frame decryption leads to out-of-bounds read and write
Source: CVE Program / CVE List V5
Vulnerability Description
ieee802154_decipher_data_frame() in subsys/net/l2/ieee802154/ieee802154_frame.c computed payload_len = net_pkt_get_len(pkt) - ll_hdr_len - authtag_len without first checking that the received frame is at least ll_hdr_len + authtag_len bytes long. All three variables are uint8_t, so a frame whose payload is shorter than the configured authentication tag makes the subtraction wrap around to a large value (up to 255). The wrapped length is passed unchanged to ieee802154_decrypt_auth() and on to the CCM operation as cipher_pkt.in_len/out_buf_max, with apkt->tag pointing at frame + ll_hdr_len + payload_len. Because the receive buffer is allocated to the exact length of the frame received from the radio driver, the crypto layer then reads several hundred bytes past the end of the packet buffer and writes the same number of decrypted bytes back over it in place. The frame's authentication tag is only verified after this processing has taken place, so no key material, association or prior authentication is needed — a single crafted short frame from any device in radio range is sufficient. Frame validation in ieee802154_validate_frame() does not prevent it: a data frame is accepted with a one-byte payload. The result is an out-of-bounds read and an out-of-bounds write of up to roughly 240 bytes into the adjacent network-buffer pool, corrupting other packets or allocator metadata and typically faulting the target. The out-of-bounds content is not attacker-chosen (it is ciphertext XOR keystream over out-of-bounds memory) and the frame is dropped when tag verification fails, so the primary impact is memory corruption and denial of service rather than information disclosure. Exposure is limited to configurations that enable the experimental CONFIG_NET_L2_IEEE802154_SECURITY option, select a crypto device via CONFIG_NET_L2_IEEE802154_SECURITY_CRYPTO_DEV_NAME, and have established a security session with a level other than IEEE802154_SECURITY_LEVEL_NONE; with security disabled or at level NONE the tag length is zero and no underflow occurs. The fix rejects frames shorter than ll_hdr_len + authtag_len before the subtraction, and adds the matching guard on the transmit side in ieee802154_create_data_frame().
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
整数下溢(超界折返)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
zephyrproject zephyr 3.2.0 ~ 4.4.2 -

II. Public POCs for CVE-2026-19186

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19186

请登录查看更多情报信息。

Other References for CVE-2026-19186 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-19186

No comments yet


Leave a comment