CVE-2026-18415
Received Received - Intake

Buffer Overflow in Zephyr RTOS IEEE 802.15.4 Stack

Vulnerability report for CVE-2026-18415, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Zephyr Project

Description

ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with CONFIG_NET_L2_IEEE802154_FRAGMENT enabled (the default whenever CONFIG_NET_6LO is set), the branch taken when 6LoWPAN fragmentation is not required performed an unchecked net_buf_add_mem(frame_buf, pkt_buf->data, pkt_buf->len). The only guard was __ASSERT_NO_MSG() inside net_buf_simple_add(), which is compiled out without CONFIG_ASSERT, so an oversized packet silently overran the frame buffer. The defect is not reachable from the radio: for NET_AF_INET6 packets ieee802154_6lo_encode_pkt() compares the whole packet length against IEEE802154_MTU and takes the fragmentation path when it does not fit, so every buffer copied on the unfragmented branch is within bounds. It is reachable through NET_AF_PACKET sockets bound to an 802.15.4 interface: for NET_SOCK_RAW the 6LoWPAN block is skipped entirely and for NET_SOCK_DGRAM it returns early on the address-family test, leaving no length validation anywhere on the transmit path (net_context_sendto() and net_if_tx() apply none, and pkt_buffer_length() does not clamp the allocation for this L2). An application β€” or, in a CONFIG_USERSPACE build, an unprivileged application thread using the zsock_socket()/zsock_sendto() syscalls β€” can therefore drive a supervisor-mode out-of-bounds write of chosen bytes past the 125-byte pool buffer. With the default CONFIG_NET_BUF_FIXED_DATA_SIZE of 128 bytes the overrun is bounded to roughly ll_hdr_len + 3 bytes; with CONFIG_NET_BUF_VARIABLE_DATA_SIZE a single storage buffer can be as large as CONFIG_NET_PKT_BUF_TX_DATA_POOL_SIZE, making the overrun far larger. The consequence is corruption of memory adjacent to the pool, with a crash or further compromise of kernel state as the practical impact. The fix validates ll_hdr_len + net_pkt_get_len(pkt) + authtag_len against IEEE802154_MTU before any copy and adds a tailroom-checking copy_pkt_to_frame() helper that returns -EMSGSIZE instead of overrunning the buffer. The same change also linearizes the whole net_buf chain into one MAC frame, so packet storage boundaries no longer become frame boundaries on the wire.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr to 125 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a buffer overflow in the ieee802154_send() function of the Zephyr RTOS network stack. When sending packets via NET_AF_PACKET sockets on an 802.15.4 interface, the function copies packet data into a fixed 125-byte buffer without proper length validation. This allows an attacker to write beyond the buffer's bounds, potentially corrupting adjacent memory and causing kernel crashes or further compromise.

Detection Guidance

This vulnerability is specific to Zephyr RTOS with IEEE 802.15.4 L2 stack and requires local access via NET_AF_PACKET sockets. Detection would involve checking for oversized packets sent through 802.15.4 interfaces or kernel crashes due to buffer overruns. No standard commands exist as it requires custom application testing.

Impact Analysis

An attacker with access to the system could exploit this flaw to execute arbitrary code in kernel mode, crash the system, or escalate privileges. The impact depends on the system configuration: with default settings, the overflow is limited to a few bytes, but with variable data sizes enabled, the overrun could be much larger, increasing the risk of severe system compromise.

Compliance Impact

This vulnerability allows an application to cause a kernel memory corruption via an out-of-bounds write, which could lead to system crashes or further compromise of kernel state. Such instability or compromise could result in unauthorized access to sensitive data or disruption of services, potentially violating compliance requirements under GDPR (e.g., integrity and confidentiality of personal data) and HIPAA (e.g., integrity and availability of protected health information).

Mitigation Strategies

Apply the vendor fix which validates packet length against IEEE802154_MTU before copying. Disable CONFIG_NET_L2_IEEE802154_FRAGMENT if not needed. Restrict access to NET_AF_PACKET sockets. Update to a patched Zephyr version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18415. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart