Impact
The vulnerability lies in the gptp_mi_qualify_announce() function, which walks the Path Trace TLV of an IEEE 802.1AS Announce message using a loop bound taken solely from the attacker‑controlled field announce->steps_removed. Because the loop does not validate against the advertised tlv.len value, an attacker can cause the memcmp() inside the loop to read far beyond the end of the received frame. The read data are only used for a comparison and are never returned, so no sensitive information is exposed. However, the over‑read can cross a network buffer pool boundary into unmapped or MPU‑protected memory, leading the networking receive thread to fault and terminate. The result is a denial‑of‑service condition for the device processing the malformed gPTP packet.
Affected Systems
Zephyr RTOS releases that enable the opt‑in, experimental CONFIG_NET_GPTP configuration (the TSN/AVB networking stack). Any build that compiles with this option and accepts gPTP Announce frames is potentially affected; the specific affected Zephyr versions are not enumerated in the advisory.
Risk and Exploitability
The CVSS score of 4.3 marks this flaw as low severity, and the EPSS score of 0.00238 indicates a very low likelihood of exploitation. It is not listed in CISA’s KEV catalog. An attacker must be on the same Ethernet segment and is not required to authenticate. The vulnerability can be triggered by sending a single crafted Announce frame with tlv.len = 0 and steps_removed = 254. Because the packet passes the length check and the handling code does not perform authentication, the denial of service can be achieved over an unauthenticated L2 attack. The risk is moderate in environments that use TSN/AVB protocols and expose gPTP traffic to untrusted devices on the same segment.
OpenCVE Enrichment