Out-of-Bounds Read Vulnerability in Zephyr's Precision Time Protocol Handler
CVE-2026-12632
6.5MEDIUM
What is CVE-2026-12632?
The Precision Time Protocol (PTP) within Zephyr contains a flaw in its message handler that allows attacker-defined message types to bypass bounds checks, leading to potential out-of-bounds reads and enabling denial of service attacks. By exploiting this flaw, an attacker can send a PTP frame with an invalid type, resulting in access to memory beyond allocated buffers. This vulnerability is particularly dangerous because it can be triggered remotely over the network without authentication, making any vulnerable node susceptible to exploitation.
Affected Version(s)
zephyr 3.7.0 < 4.4.2
