Impact
In the Zephyr RTOS network stack, net_route_ipv6_packet() resolves a neighbor’s link‑layer address without checking if the neighbor cache entry actually has one. An unresolved neighbor yields an index of 0xff, and the subsequent lookup returns a pointer to data beyond the end of the link‑layer address array. If CONFIG_ASSERT is enabled the assertion fires, causing a panic and a repeatable remote denial of service. With assertions disabled the stale pointer is used in a memcmp and, if the length field passes a boundary check, up to eight bytes of unrelated static RAM are copied into the outgoing frame’s destination address and transmitted, leaking a small amount of memory to any listening device.
Affected Systems
The vulnerability exists in the Zephyr RTOS network stack for any build that enables IPv6 routing (CONFIG_NET_IPV6_ROUTE) while the neighbor cache is active. All Zephyr releases prior to the commit b0b0e8973d1967114adbb9ed1611d448b5a46519 are affected. The buggy logic resides in subsys/net/ip/route_ipv6.c, subsys/net/ip/ipv6.c, and subsys/net/ip/nbr.c.
Risk and Exploitability
With a CVSS score of 7.1 and no EPSS value available, the flaw is considered medium severity. It is not in the CISA KEV catalog. The attack can be performed by an unauthenticated adversary on the same Ethernet link who induces an unresolved neighbor entry by sending crafted neighbor solicitation messages or a router advertisement lacking a source link‑layer address. No elevated privileges or special hardware are required; the flaw is confined to the neighbor cache logic and the out‑of‑bounds index is fixed, so the likelihood of successful exploitation is moderate, leading to denial of service or a small disclosure of static memory.
OpenCVE Enrichment