Impact
An out‑of‑bounds read occurs in the gPTP receive routine when a short Ethernet frame is processed. The header pointer returned by GPTP_HDR() is dereferenced without ensuring the payload is at least 34 bytes, causing the code to read beyond the bounds of the received packet. The flaw manifests as a memory disclosure of stale or unrelated data; there is no write, crash, or denial of service. The weakness corresponds to CWE‑125.
Affected Systems
The vulnerability affects devices running the Zephyr RTOS with CONFIG_NET_GPTP enabled on a network interface configured as a gPTP port. An attacker must be able to send Ethernet frames of type 0x88F7 to the PTP multicast address, and the link must accept undersized frames (e.g., a TAP driver or a MAC that permits frames shorter than the minimum Ethernet payload).
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An unauthenticated peer on the same network link can send a crafted short frame to trigger the read, provided the interface is listening for GPTP frames and the link allows sub‑minimum frames. The impact is the leakage of memory contents; there is no escalation or denial of service. The attack is straightforward for an attacker with network access to the device.
OpenCVE Enrichment