Description
net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_reachable = 3*base/2 using integer division. When base_reachable_time is 1, both min_reachable and the modulus collapse so the function returns 0, and net_if_ipv6_set_reachable_time() stores that 0 into ipv6->reachable_time.

The base_reachable_time is attacker-controlled: handle_ra_input() in subsys/net/ip/ipv6_nbr.c accepts the Reachable Time field of an incoming Router Advertisement whenever it is nonzero and <= MAX_REACHABLE_TIME, so a single unauthenticated, link-local RA carrying a Reachable Time of 1 drives the computed reachable time to 0. Router Advertisements are unauthenticated by default and require only adjacency to the target link.

When a neighbor is subsequently confirmed reachable, net_ipv6_nbr_set_reachable_timer() reads the value and executes NET_ASSERT(time, "Zero reachable timeout!"). On builds with CONFIG_ASSERT enabled this triggers a fatal kernel assertion — a remote denial of service; on builds without assertions the reachable timer is armed with K_MSEC(0) and fires immediately, forcing reachable neighbors into perpetual re-solicitation (STALE), degrading Neighbor Discovery. The impact is limited to availability; there is no memory-safety, confidentiality, or integrity consequence.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Immediate Patch
AI Analysis

Impact

net_if_ipv6_calc_reachable_time() calculates a device’s IPv6 neighbor reachable timeout from a base value that an attacker can supply via a crafted Router Advertisement. This is a CWE-617 weakness. When the base is set to 1, the calculation collapses to zero and the kernel later asserts on this zero value. In builds that enable assertions this causes a fatal kernel crash; in builds without assertions the timer is set to zero, triggering continuous neighbor solicitations and severely degrading IPv6 neighbor discovery. The attack does not leak information or corrupt memory, and its effect is limited to availability.

Affected Systems

All Zephyr Project ROC kernels that include the current implementation of net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c are affected. The vulnerability is realized through any link‑local Router Advertisement featuring a Reachable Time of 1, regardless of the target device’s firmware version, so any custom or shipping Zephyr build that processes RA fields without additional filtering is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score is 0.002, indicating a low but non‑zero exploitation probability, but the absence of past exploitation does not diminish the fact that an unauthenticated, link‑local attacker can trigger the condition by simply sending a crafted RA. Because Router Advertisements are normally unauthenticated and the attacker only needs adjacency on the local link, the risk of exploitation is high in exposed or poorly secured networks. Although the vulnerability is not listed in CISA’s KEV catalog, the combination of a straightforward exploit vector (link‑local RA) and a reversible denial‑of‑service payload warrants serious attention.

Generated by OpenCVE AI on September 20, 2026 at 23:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Zephyr patch at commit 251079ed50464aa0976eb0738a5afbe009cc9d60 or upgrade to a Zephyr release that includes the corrected reachable time calculation.
  • Configure the kernel to reject Router Advertisements that carry a Reachable Time of 1, for example by setting a minimum threshold in the RA processing logic or by trimming the accepted range of the Reachable Time field.
  • Re‑enable or enable kernel assertions on critical paths if the system configuration permits so that accidental zero reachable timers trigger a safe failure rather than a silent fault; alternatively, ensure that the system has a rapid reboot or recovery mechanism in place to mitigate longer‑running denial‑of‑service effects.

Generated by OpenCVE AI on September 20, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_reachable = 3*base/2 using integer division. When base_reachable_time is 1, both min_reachable and the modulus collapse so the function returns 0, and net_if_ipv6_set_reachable_time() stores that 0 into ipv6->reachable_time. The base_reachable_time is attacker-controlled: handle_ra_input() in subsys/net/ip/ipv6_nbr.c accepts the Reachable Time field of an incoming Router Advertisement whenever it is nonzero and <= MAX_REACHABLE_TIME, so a single unauthenticated, link-local RA carrying a Reachable Time of 1 drives the computed reachable time to 0. Router Advertisements are unauthenticated by default and require only adjacency to the target link. When a neighbor is subsequently confirmed reachable, net_ipv6_nbr_set_reachable_timer() reads the value and executes NET_ASSERT(time, "Zero reachable timeout!"). On builds with CONFIG_ASSERT enabled this triggers a fatal kernel assertion — a remote denial of service; on builds without assertions the reachable timer is armed with K_MSEC(0) and fires immediately, forcing reachable neighbors into perpetual re-solicitation (STALE), degrading Neighbor Discovery. The impact is limited to availability; there is no memory-safety, confidentiality, or integrity consequence.
Title Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advertisement causes assertion/DoS
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-14T19:02:46.400Z

Reserved: 2026-07-15T17:38:09.892Z

Link: CVE-2026-15893

cve-icon Vulnrichment

Updated: 2026-09-14T19:02:41.847Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T19:17:14.627

Modified: 2026-09-14T21:10:41.650

Link: CVE-2026-15893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses