Impact
net_if_ipv6_calc_reachable_time() calculates a device’s IPv6 neighbor reachable timeout from a base value that an attacker can supply via a crafted Router Advertisement. This is a CWE-617 weakness. When the base is set to 1, the calculation collapses to zero and the kernel later asserts on this zero value. In builds that enable assertions this causes a fatal kernel crash; in builds without assertions the timer is set to zero, triggering continuous neighbor solicitations and severely degrading IPv6 neighbor discovery. The attack does not leak information or corrupt memory, and its effect is limited to availability.
Affected Systems
All Zephyr Project ROC kernels that include the current implementation of net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c are affected. The vulnerability is realized through any link‑local Router Advertisement featuring a Reachable Time of 1, regardless of the target device’s firmware version, so any custom or shipping Zephyr build that processes RA fields without additional filtering is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is 0.002, indicating a low but non‑zero exploitation probability, but the absence of past exploitation does not diminish the fact that an unauthenticated, link‑local attacker can trigger the condition by simply sending a crafted RA. Because Router Advertisements are normally unauthenticated and the attacker only needs adjacency on the local link, the risk of exploitation is high in exposed or poorly secured networks. Although the vulnerability is not listed in CISA’s KEV catalog, the combination of a straightforward exploit vector (link‑local RA) and a reversible denial‑of‑service payload warrants serious attention.
OpenCVE Enrichment