CVE-2026-19577
Received Received - Intake

Out-of-Bounds Read in Zephyr RTOS IPv6 Neighbor Cache

Vulnerability report for CVE-2026-19577, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

net_route_ipv6_packet() in subsys/net/ip/route_ipv6.c resolved the nexthop's link-layer address with net_nbr_get_lladdr(nbr->idx) without first checking whether the neighbor cache entry actually had a linked link-layer address. An unresolved neighbor carries idx == NET_NBR_LLADDR_UNKNOWN (0xff), and net_nbr_get_lladdr() in subsys/net/ip/nbr.c performs no runtime bounds check beyond a NET_ASSERT, returning &net_neighbor_lladdr[255] β€” roughly 2.5 KB past the end of an array whose default size is CONFIG_NET_IPV6_MAX_NEIGHBORS (8). Because the returned pointer is never NULL, the following lladdr == NULL guard does not catch it. The function is reached from ipv6_route_packet() in subsys/net/ip/ipv6.c for every received unicast IPv6 packet whose destination is not a local address on the receiving interface; CONFIG_NET_IPV6_ROUTE is enabled by default whenever the IPv6 neighbor cache is, so no router or forwarding configuration is needed. net_route_ipv6_get_info() returns the packet's destination itself as the nexthop when a neighbor cache entry for it exists, and the cache lookup does not skip INCOMPLETE entries. An unauthenticated attacker on the same link can therefore force the unresolved state β€” for example by eliciting traffic to a spoofed, non-existent neighbor address so that net_ipv6_send_ns() creates an INCOMPLETE entry, or by sending a Router Advertisement with no source link-layer address option, which creates a persistently unresolved router neighbor β€” and then send a packet addressed to that neighbor. The result is an out-of-bounds read at a fixed index past the neighbor link-layer address array. On builds with CONFIG_ASSERT enabled the assertion fires and the device panics, giving a repeatable remote denial of service. With assertions disabled, the stale out-of-bounds struct net_linkaddr drives a memcmp() over an attacker-uninfluenced length and, when its len byte passes the NET_LINK_ADDR_MAX_LENGTH check, up to 8 bytes of unrelated static RAM are copied into the outgoing frame's destination link-layer address and transmitted on the link, disclosing them to any listener. There is no out-of-bounds write and the offset is not attacker-controlled, which bounds the impact.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 1.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read in Zephyr RTOS's IPv6 routing code. When processing IPv6 packets, the system fails to check if a neighbor has a valid link-layer address before accessing it. This leads to reading memory outside the intended array bounds, potentially causing crashes or leaking data.

Detection Guidance

Detecting this vulnerability requires checking Zephyr RTOS versions and network traffic patterns. Inspect Zephyr version with git describe or version.h. Monitor for IPv6 packet forwarding failures or neighbor cache issues. Enable logging for net_route_ipv6_packet() and net_nbr_get_lladdr() functions if possible.

Impact Analysis

An attacker on the same network can exploit this to crash devices using affected Zephyr versions, causing denial of service. Without crash protection, it may also expose small amounts of unrelated memory data in transmitted packets.

Compliance Impact

This vulnerability primarily impacts system availability through remote denial of service when assertions are enabled, which could disrupt services handling sensitive data. With assertions disabled, it may expose small amounts of unrelated static RAM in transmitted frames, potentially leaking configuration details. This could indirectly affect compliance by compromising data confidentiality if sensitive information is inadvertently disclosed in network traffic.

Mitigation Strategies

Upgrade Zephyr RTOS to version 4.5.0 or later. Disable IPv6 routing if not required. Implement network segmentation to limit attack surface. Monitor for neighbor cache inconsistencies or unexpected panics.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19577. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart