Type Confusion in Sierra Wireless HL78xx GNSS Driver
CVE-2026-15461
5.3MEDIUM
What is CVE-2026-15461?
The Sierra Wireless HL78xx modem GNSS driver contains a type confusion vulnerability due to improper struct member alignment. This issue arises from the generic NMEA0183 match data being mispositioned within the driver structure, leading to incorrect data handling in GNSS signal parsing. When the device receives NMEA sentences, it can cause the GGA/RMC callbacks to write parsed fix data into an incorrect memory location. Consequently, this creates a risk of crashes (denial of service) or potential adjacent-memory corruption in certain environments. Exploitation relies on GNSS signal manipulation, necessitating that the satellites feature is active, thus making successful attacks challenging.
Affected Version(s)
zephyr 4.4.0 < 4.4.2
