Description
gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken solely from the attacker-controlled wire field announce->steps_removed (accepted up to 254), never from announce->tlv.len, which is the field that states how many identities the TLV actually carries. Because path_sequence is the flexible member of the wire TLV (struct gptp_path_trace_tlv) and GPTP_ANNOUNCE() yields a raw pointer into the received packet buffer, the memcmp() inside the loop can address memory well past the end of the received frame.

The stack's only length validation, GPTP_ANNOUNCE_CHECK_LEN(), requires the received gPTP payload to be exactly 68 + tlv.len bytes — so it does not constrain the loop, it guarantees the data is absent. An unauthenticated attacker on the same Ethernet segment can send a single Announce frame declaring tlv.len = 0 with steps_removed = 254; the frame passes the length check and reception path (net_gptp_recv() → gptp_handle_msg() → gptp_mi_qualify_announce()), which performs no authentication, and the loop then reads 255 entries of 8 bytes each — about 2 KB — beyond the end of the network buffer.

The impact is an out-of-bounds read. The bytes read are only used as a memcmp() operand and are never returned to the attacker, so there is no meaningful information disclosure; the practical risk is that the overread crosses a network buffer pool boundary into unmapped or MPU-protected memory and faults the networking RX thread, causing a denial of service. Exposure is limited to builds that enable the opt-in, experimental CONFIG_NET_GPTP (TSN/AVB deployments) and to attackers with layer-2 adjacency, since gPTP frames are sent to a link-local multicast address and are not routed.

The fix computes the true entry count as tlv.len / GPTP_CLOCK_ID_LEN and rejects the announce when steps_removed + 1 exceeds it, so the loop can no longer run past the data the packet-length check proved present.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds read that can crash the networking receive thread, causing denial of service to the affected device
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the gptp_mi_qualify_announce() function, which walks the Path Trace TLV of an IEEE 802.1AS Announce message using a loop bound taken solely from the attacker‑controlled field announce->steps_removed. Because the loop does not validate against the advertised tlv.len value, an attacker can cause the memcmp() inside the loop to read far beyond the end of the received frame. The read data are only used for a comparison and are never returned, so no sensitive information is exposed. However, the over‑read can cross a network buffer pool boundary into unmapped or MPU‑protected memory, leading the networking receive thread to fault and terminate. The result is a denial‑of‑service condition for the device processing the malformed gPTP packet.

Affected Systems

Zephyr RTOS releases that enable the opt‑in, experimental CONFIG_NET_GPTP configuration (the TSN/AVB networking stack). Any build that compiles with this option and accepts gPTP Announce frames is potentially affected; the specific affected Zephyr versions are not enumerated in the advisory.

Risk and Exploitability

The CVSS score of 4.3 marks this flaw as low severity, and the EPSS score of 0.00238 indicates a very low likelihood of exploitation. It is not listed in CISA’s KEV catalog. An attacker must be on the same Ethernet segment and is not required to authenticate. The vulnerability can be triggered by sending a single crafted Announce frame with tlv.len = 0 and steps_removed = 254. Because the packet passes the length check and the handling code does not perform authentication, the denial of service can be achieved over an unauthenticated L2 attack. The risk is moderate in environments that use TSN/AVB protocols and expose gPTP traffic to untrusted devices on the same segment.

Generated by OpenCVE AI on September 19, 2026 at 18:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Zephyr security fix that validates steps_removed against the actual tlv.len value, preventing out‑of‑bounds reads
  • If TSN/AVB functionality is not required, disable CONFIG_NET_GPTP in the Zephyr configuration to eliminate the vulnerable code path
  • Restrict gPTP Announce traffic to trusted devices by segmenting the network or applying ACLs that block malformed gPTP frames from untrusted sources
  • Monitor the device for receive‑thread crashes or kernel exceptions indicative of the over‑read fault and plan for automatic recovery or reboot procedures

Generated by OpenCVE AI on September 19, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken solely from the attacker-controlled wire field announce->steps_removed (accepted up to 254), never from announce->tlv.len, which is the field that states how many identities the TLV actually carries. Because path_sequence is the flexible member of the wire TLV (struct gptp_path_trace_tlv) and GPTP_ANNOUNCE() yields a raw pointer into the received packet buffer, the memcmp() inside the loop can address memory well past the end of the received frame. The stack's only length validation, GPTP_ANNOUNCE_CHECK_LEN(), requires the received gPTP payload to be exactly 68 + tlv.len bytes — so it does not constrain the loop, it guarantees the data is absent. An unauthenticated attacker on the same Ethernet segment can send a single Announce frame declaring tlv.len = 0 with steps_removed = 254; the frame passes the length check and reception path (net_gptp_recv() → gptp_handle_msg() → gptp_mi_qualify_announce()), which performs no authentication, and the loop then reads 255 entries of 8 bytes each — about 2 KB — beyond the end of the network buffer. The impact is an out-of-bounds read. The bytes read are only used as a memcmp() operand and are never returned to the attacker, so there is no meaningful information disclosure; the practical risk is that the overread crosses a network buffer pool boundary into unmapped or MPU-protected memory and faults the networking RX thread, causing a denial of service. Exposure is limited to builds that enable the opt-in, experimental CONFIG_NET_GPTP (TSN/AVB deployments) and to attackers with layer-2 adjacency, since gPTP frames are sent to a link-local multicast address and are not routed. The fix computes the true entry count as tlv.len / GPTP_CLOCK_ID_LEN and rejects the announce when steps_removed + 1 exceeds it, so the loop can no longer run past the data the packet-length check proved present.
Title Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-09-18T16:42:41.192Z

Reserved: 2026-07-21T21:42:59.661Z

Link: CVE-2026-16514

cve-icon Vulnrichment

Updated: 2026-09-18T16:41:58.223Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:05.753

Modified: 2026-09-18T19:11:57.760

Link: CVE-2026-16514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:15Z

Weaknesses