Type Confusion in Sierra Wireless HL78xx GNSS Driver
CVE-2026-15461

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-15461?

The Sierra Wireless HL78xx modem GNSS driver contains a type confusion vulnerability due to improper struct member alignment. This issue arises from the generic NMEA0183 match data being mispositioned within the driver structure, leading to incorrect data handling in GNSS signal parsing. When the device receives NMEA sentences, it can cause the GGA/RMC callbacks to write parsed fix data into an incorrect memory location. Consequently, this creates a risk of crashes (denial of service) or potential adjacent-memory corruption in certain environments. Exploitation relies on GNSS signal manipulation, necessitating that the satellites feature is active, thus making successful attacks challenging.

Affected Version(s)

zephyr 4.4.0 < 4.4.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.