Memory Leak in Infineon Airoc Wi-Fi Driver Affecting Device Connectivity
CVE-2026-12999

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-12999?

The Infineon Airoc Wi-Fi driver contains a vulnerability that leads to a memory leak during outbound packet transmission failures. The driver's transmit callback allocates buffers from a limited pool for every outgoing packet. If a transmission fails, these buffers are not released properly, leading to a depletion of available resources. Attackers can exploit this by causing synchronous send failures, resulting in permanent denial of service until the affected device is rebooted. The issue has been addressed in the latest fix, which ensures proper handling of buffer allocation failures.

Affected Version(s)

zephyr 3.6.0 < 4.4.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.