Description
net_route_ipv6_packet() in subsys/net/ip/route_ipv6.c resolved the nexthop's link-layer address with net_nbr_get_lladdr(nbr->idx) without first checking whether the neighbor cache entry actually had a linked link-layer address. An unresolved neighbor carries idx == NET_NBR_LLADDR_UNKNOWN (0xff), and net_nbr_get_lladdr() in subsys/net/ip/nbr.c performs no runtime bounds check beyond a NET_ASSERT, returning &net_neighbor_lladdr[255] — roughly 2.5 KB past the end of an array whose default size is CONFIG_NET_IPV6_MAX_NEIGHBORS (8). Because the returned pointer is never NULL, the following lladdr == NULL guard does not catch it.

The function is reached from ipv6_route_packet() in subsys/net/ip/ipv6.c for every received unicast IPv6 packet whose destination is not a local address on the receiving interface; CONFIG_NET_IPV6_ROUTE is enabled by default whenever the IPv6 neighbor cache is, so no router or forwarding configuration is needed. net_route_ipv6_get_info() returns the packet's destination itself as the nexthop when a neighbor cache entry for it exists, and the cache lookup does not skip INCOMPLETE entries. An unauthenticated attacker on the same link can therefore force the unresolved state — for example by eliciting traffic to a spoofed, non-existent neighbor address so that net_ipv6_send_ns() creates an INCOMPLETE entry, or by sending a Router Advertisement with no source link-layer address option, which creates a persistently unresolved router neighbor — and then send a packet addressed to that neighbor.

The result is an out-of-bounds read at a fixed index past the neighbor link-layer address array. On builds with CONFIG_ASSERT enabled the assertion fires and the device panics, giving a repeatable remote denial of service. With assertions disabled, the stale out-of-bounds struct net_linkaddr drives a memcmp() over an attacker-uninfluenced length and, when its len byte passes the NET_LINK_ADDR_MAX_LENGTH check, up to 8 bytes of unrelated static RAM are copied into the outgoing frame's destination link-layer address and transmitted on the link, disclosing them to any listener. There is no out-of-bounds write and the offset is not attacker-controlled, which bounds the impact.
Published: 2026-10-11
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Remote Denial of Service and potential Information Disclosure
Action: Patch Now
AI Analysis

Impact

In the Zephyr RTOS network stack, net_route_ipv6_packet() resolves a neighbor’s link‑layer address without checking if the neighbor cache entry actually has one. An unresolved neighbor yields an index of 0xff, and the subsequent lookup returns a pointer to data beyond the end of the link‑layer address array. If CONFIG_ASSERT is enabled the assertion fires, causing a panic and a repeatable remote denial of service. With assertions disabled the stale pointer is used in a memcmp and, if the length field passes a boundary check, up to eight bytes of unrelated static RAM are copied into the outgoing frame’s destination address and transmitted, leaking a small amount of memory to any listening device.

Affected Systems

The vulnerability exists in the Zephyr RTOS network stack for any build that enables IPv6 routing (CONFIG_NET_IPV6_ROUTE) while the neighbor cache is active. All Zephyr releases prior to the commit b0b0e8973d1967114adbb9ed1611d448b5a46519 are affected. The buggy logic resides in subsys/net/ip/route_ipv6.c, subsys/net/ip/ipv6.c, and subsys/net/ip/nbr.c.

Risk and Exploitability

With a CVSS score of 7.1 and no EPSS value available, the flaw is considered medium severity. It is not in the CISA KEV catalog. The attack can be performed by an unauthenticated adversary on the same Ethernet link who induces an unresolved neighbor entry by sending crafted neighbor solicitation messages or a router advertisement lacking a source link‑layer address. No elevated privileges or special hardware are required; the flaw is confined to the neighbor cache logic and the out‑of‑bounds index is fixed, so the likelihood of successful exploitation is moderate, leading to denial of service or a small disclosure of static memory.

Generated by OpenCVE AI on October 11, 2026 at 18:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zephyr to a version that includes the patch from commit b0b0e8973d1967114adbb9ed1611d448b5a46519 or apply the patch manually
  • If IPv6 routing or neighbor cache is not required, disable CONFIG_NET_IPV6_ROUTE or configure the stack to avoid routing through the vulnerable code
  • Enable CONFIG_ASSERT in production builds so that unreachable neighbors trigger a panic rather than silent memory leakage during operation

Generated by OpenCVE AI on October 11, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Sun, 11 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description net_route_ipv6_packet() in subsys/net/ip/route_ipv6.c resolved the nexthop's link-layer address with net_nbr_get_lladdr(nbr->idx) without first checking whether the neighbor cache entry actually had a linked link-layer address. An unresolved neighbor carries idx == NET_NBR_LLADDR_UNKNOWN (0xff), and net_nbr_get_lladdr() in subsys/net/ip/nbr.c performs no runtime bounds check beyond a NET_ASSERT, returning &net_neighbor_lladdr[255] — roughly 2.5 KB past the end of an array whose default size is CONFIG_NET_IPV6_MAX_NEIGHBORS (8). Because the returned pointer is never NULL, the following lladdr == NULL guard does not catch it. The function is reached from ipv6_route_packet() in subsys/net/ip/ipv6.c for every received unicast IPv6 packet whose destination is not a local address on the receiving interface; CONFIG_NET_IPV6_ROUTE is enabled by default whenever the IPv6 neighbor cache is, so no router or forwarding configuration is needed. net_route_ipv6_get_info() returns the packet's destination itself as the nexthop when a neighbor cache entry for it exists, and the cache lookup does not skip INCOMPLETE entries. An unauthenticated attacker on the same link can therefore force the unresolved state — for example by eliciting traffic to a spoofed, non-existent neighbor address so that net_ipv6_send_ns() creates an INCOMPLETE entry, or by sending a Router Advertisement with no source link-layer address option, which creates a persistently unresolved router neighbor — and then send a packet addressed to that neighbor. The result is an out-of-bounds read at a fixed index past the neighbor link-layer address array. On builds with CONFIG_ASSERT enabled the assertion fires and the device panics, giving a repeatable remote denial of service. With assertions disabled, the stale out-of-bounds struct net_linkaddr drives a memcmp() over an attacker-uninfluenced length and, when its len byte passes the NET_LINK_ADDR_MAX_LENGTH check, up to 8 bytes of unrelated static RAM are copied into the outgoing frame's destination link-layer address and transmitted on the link, disclosing them to any listener. There is no out-of-bounds write and the offset is not attacker-controlled, which bounds the impact.
Title Out-of-bounds read in IPv6 route forwarding when the nexthop neighbor has no link-layer address
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-10-11T17:14:55.032Z

Reserved: 2026-08-11T19:57:38.944Z

Link: CVE-2026-19577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T18:16:58.433

Modified: 2026-10-11T18:16:58.433

Link: CVE-2026-19577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T18:30:19Z

Weaknesses