Impact
The vulnerability is in Zephyr’s IPv6 stack, where net_icmpv6_send_error() incorrectly implements RFC 4443 suppression rules. It allows a malicious or accidental packet to trigger the generation of ICMPv6 Parameter Problem messages for packets sent to the local all‑nodes multicast group ff02::1 or from a multicast source address. Each triggered ICMPv6 response is sent to the spoofed source or multicast address, creating an amplification effect that can flood the local link and its upstream networks. The attack does not compromise memory safety and cannot overflow buffers, but it can cause degraded availability for routers and endpoints and obscure the attacker’s identity by making multiple nodes appear to send responses.
Affected Systems
All Zephyr RTOS-based devices that run a version of the kernel before the patch that adds proper suppression checks – specifically before the commit ba4247b24ddd3a5360b617e3ca17131ca9e8026a. The issue is present in any configuration that enables IPv6 stack operation and is reachable on a local link.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, and the EPSS score of <1% indicates a very low exploitation probability, suggesting that exploitation probability is uncertain but potentially significant under the right conditions. The vulnerability is not listed in the CISA KEV catalog, yet it can be leveraged by an attacker with local link access to conduct a reflector style denial‑of‑service or to obscure their attack traffic. The impact is amplified in low‑power mesh networks such as 802.15.4/Thread, where multicast packets are hop‑by‑hop flooded.
OpenCVE Enrichment