Out-of-Bounds Read Vulnerability in Zephyr's Precision Time Protocol Handler
CVE-2026-12632

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-12632?

The Precision Time Protocol (PTP) within Zephyr contains a flaw in its message handler that allows attacker-defined message types to bypass bounds checks, leading to potential out-of-bounds reads and enabling denial of service attacks. By exploiting this flaw, an attacker can send a PTP frame with an invalid type, resulting in access to memory beyond allocated buffers. This vulnerability is particularly dangerous because it can be triggered remotely over the network without authentication, making any vulnerable node susceptible to exploitation.

Affected Version(s)

zephyr 3.7.0 < 4.4.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.