Out-of-Bounds Read and Write Vulnerability in Zephyr's IEEE 802.15.4
CVE-2026-19186
What is CVE-2026-19186?
An out-of-bounds read and write vulnerability exists in the ieee802154_decipher_data_frame function of Zephyr RTOS's IEEE 802.15.4 security stack. This flaw arises when the payload length is calculated without verifying that the received frame adheres to the necessary length. As a result, if a data frame with a short payload is received, it leads to memory corruption, potentially affecting adjacent network-buffer pools and causing denial of service. This vulnerability particularly impacts systems where security configurations are enabled and a security session is established. The correct implementation now ensures that frames shorter than the required length are rejected, enhancing the overall security of the data communication layer.
Affected Version(s)
zephyr 3.2.0 <= 4.4.2
