Buffer Overflow Vulnerability in Zephyr Project's IEEE 802.15.4 Implementation
CVE-2026-18415
6.3MEDIUM
What is CVE-2026-18415?
An unchecked buffer overflow vulnerability exists in the Zephyr Project’s IEEE 802.15.4 networking stack that could allow an application or unprivileged thread to cause a supervisor-mode out-of-bounds write. This occurs due to inadequate validation when handling NET_AF_PACKET sockets, specifically bypassing crucial length checks and allowing oversized packets to overwrite adjacent memory. If left unaddressed, this could lead to memory corruption, application crashes, or potential kernel compromises. The vulnerability is mitigated by introducing length validations to prevent overrun scenarios.
Affected Version(s)
zephyr 3.2.0 < 4.4.2
