Buffer Overflow Vulnerability in Zephyr Project's IEEE 802.15.4 Implementation
CVE-2026-18415

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-18415?

An unchecked buffer overflow vulnerability exists in the Zephyr Project’s IEEE 802.15.4 networking stack that could allow an application or unprivileged thread to cause a supervisor-mode out-of-bounds write. This occurs due to inadequate validation when handling NET_AF_PACKET sockets, specifically bypassing crucial length checks and allowing oversized packets to overwrite adjacent memory. If left unaddressed, this could lead to memory corruption, application crashes, or potential kernel compromises. The vulnerability is mitigated by introducing length validations to prevent overrun scenarios.

Affected Version(s)

zephyr 3.2.0 < 4.4.2

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.