Out-of-Bounds Read and Write Vulnerability in Zephyr's IEEE 802.15.4
CVE-2026-19186

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-19186?

An out-of-bounds read and write vulnerability exists in the ieee802154_decipher_data_frame function of Zephyr RTOS's IEEE 802.15.4 security stack. This flaw arises when the payload length is calculated without verifying that the received frame adheres to the necessary length. As a result, if a data frame with a short payload is received, it leads to memory corruption, potentially affecting adjacent network-buffer pools and causing denial of service. This vulnerability particularly impacts systems where security configurations are enabled and a security session is established. The correct implementation now ensures that frames shorter than the required length are rejected, enhancing the overall security of the data communication layer.

Affected Version(s)

zephyr 3.2.0 <= 4.4.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.