目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-19577— IPv6路由转发中越界读取漏洞

一分钟漏洞结论

影响对象
zephyrproject zephyr
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

以下是该漏洞描述信息的中文翻译: 位于 中的 函数在调用 获取下一跳(nexthop)的链路层地址时,未首先检查邻居缓存条目是否确实包含已关联的链路层地址。对于未解析的邻居,其 等于 (0xff)。此时, 中的 函数除了发出 断言外,未执行任何运行时边界检查,从而返回指向 的指针——该地址距离数组末尾约 2.5 KB,而该数组的默认大小由 (值为 8)决定。由于返回的指针永远不为 值,因此后续代码中用于检查 的防护逻辑无法捕获此异常。 该函数通过 中的 被调用,用于处理每一个目的地非接收接口本地地址的单播 IPv6

CVSS 7.1 · High

可能的 ATT&CK 技术 1 AI

T1115 · Clipboard Data

影响版本矩阵 1

厂商产品 版本范围状态
zephyrproject zephyr 1.8.0< 4.5.0 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-19577 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Out-of-bounds read in IPv6 route forwarding when the nexthop neighbor has no link-layer address
来源: CVE Program / CVE List V5
Vulnerability Description
net_route_ipv6_packet() in subsys/net/ip/route_ipv6.c resolved the nexthop's link-layer address with net_nbr_get_lladdr(nbr->idx) without first checking whether the neighbor cache entry actually had a linked link-layer address. An unresolved neighbor carries idx == NET_NBR_LLADDR_UNKNOWN (0xff), and net_nbr_get_lladdr() in subsys/net/ip/nbr.c performs no runtime bounds check beyond a NET_ASSERT, returning &net_neighbor_lladdr[255] — roughly 2.5 KB past the end of an array whose default size is CONFIG_NET_IPV6_MAX_NEIGHBORS (8). Because the returned pointer is never NULL, the following lladdr == NULL guard does not catch it. The function is reached from ipv6_route_packet() in subsys/net/ip/ipv6.c for every received unicast IPv6 packet whose destination is not a local address on the receiving interface; CONFIG_NET_IPV6_ROUTE is enabled by default whenever the IPv6 neighbor cache is, so no router or forwarding configuration is needed. net_route_ipv6_get_info() returns the packet's destination itself as the nexthop when a neighbor cache entry for it exists, and the cache lookup does not skip INCOMPLETE entries. An unauthenticated attacker on the same link can therefore force the unresolved state — for example by eliciting traffic to a spoofed, non-existent neighbor address so that net_ipv6_send_ns() creates an INCOMPLETE entry, or by sending a Router Advertisement with no source link-layer address option, which creates a persistently unresolved router neighbor — and then send a packet addressed to that neighbor. The result is an out-of-bounds read at a fixed index past the neighbor link-layer address array. On builds with CONFIG_ASSERT enabled the assertion fires and the device panics, giving a repeatable remote denial of service. With assertions disabled, the stale out-of-bounds struct net_linkaddr drives a memcmp() over an attacker-uninfluenced length and, when its len byte passes the NET_LINK_ADDR_MAX_LENGTH check, up to 8 bytes of unrelated static RAM are copied into the outgoing frame's destination link-layer address and transmitted on the link, disclosing them to any listener. There is no out-of-bounds write and the offset is not attacker-controlled, which bounds the impact.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
zephyrproject zephyr 1.8.0 ~ 4.5.0 -

二、漏洞 CVE-2026-19577 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-19577 的情报信息

请登录查看更多情报信息。

CVE-2026-19577 其他参考 (2)

同批安全公告 · zephyrproject · 2026-10-11 · 共 11 条

CVE-2026-19736 7.8 HIGH NXP MCUX TRNG熵驱动越界写入漏洞
CVE-2026-19669 7.8 HIGH 燃料计量系统调用验证器无界变长数组导致内核栈溢出
CVE-2026-19935 7.5 HIGH Zephyr蓝牙协议栈L2CAP通道使用后释放漏洞
CVE-2026-19576 6.8 MEDIUM Goodix GT911 触摸屏控制器驱动栈外写入漏洞
CVE-2026-19740 6.5 MEDIUM 蓝牙LE控制器:PHY更新过程中的RX节点泄露和可达断言漏洞
CVE-2026-19738 6.5 MEDIUM 蓝牙控制器CIS创建过程中保留RX节点泄漏及可达断言漏洞
CVE-2026-19739 6.5 MEDIUM 蓝牙LE控制器连接更新时意外LL控制PDU导致内存泄漏
CVE-2026-19737 5.5 MEDIUM ESP32 I2S驱动空指针解引用漏洞
CVE-2026-19735 4.8 MEDIUM Zephyr TCP栈可预测TCP初始序列号漏洞
CVE-2026-18418 3.4 LOW zbus 代理代理越界读取漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-19577

暂无评论


发表评论