The IPv6 neighbor-discovery code in subsys/net/ip/ipv6nbr.c processes the 6LoWPAN Context Option (6CO, RFC 6775) carried inside ICMPv6 Router Advertisements. In handlera6co() the 8-bit contextlen field is taken directly from the packet and was never bounded to the RFC maximum of 128. The function computes context->contextlen / 8 and then performs memset(context->prefix + contextlen, 0, sizeof(context->prefix) - context_len), where context->prefix is a fixed 16-byte array.
With contextlen between 136 and 255 (and the option length field set to 3, which the pre-fix validation accepts), contextlen / 8 evaluates to 17..31, so the memset length 16 - contextlen/8 underflows the unsigned sizet argument to roughly SIZE_MAX. This produces an unbounded out-of-bounds memset that zeroes kernel memory well past the 6lo context structure.
The defect is reachable from unauthenticated, link-local input: any host on the same link can send a crafted Router Advertisement with a 6CO option. The RA handler validates only the option length field before calling handlera6co(), so a single packet triggers the wild write. The code is compiled when CONFIGNET6LO_CONTEXT is enabled.
The impact is a reliable remote (adjacent) denial of service via memory corruption, with collateral integrity loss as the memset zeroes contiguous memory before the system faults. Router Advertisements are link-scoped and not forwarded, so the attacker must be on the same link (AV:A). The fix rejects any context_len greater than 128 before the length computation.
{
"cwe_ids": [
"CWE-787"
],
"cna_assigner": "zephyr",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12633.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12633.json"
[
{
"signature_type": "Function",
"digest": {
"function_hash": "267539371696623121120350077775344467726",
"length": 604.0
},
"target": {
"function": "handle_ra_6co",
"file": "subsys/net/ip/ipv6_nbr.c"
},
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/15e838c739be637bf23fd56a5c26f2b32079551b",
"signature_version": "v1",
"id": "CVE-2026-12633-3b7fcb39",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"204206096444958091730372478603137950800",
"338615262403669516417959998986501470228",
"85139857402039309434835499307801015552",
"271653168381252246532307486393129816758",
"20062006815393758460042036162702769065"
]
},
"target": {
"file": "subsys/net/ip/ipv6_nbr.c"
},
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/15e838c739be637bf23fd56a5c26f2b32079551b",
"signature_version": "v1",
"id": "CVE-2026-12633-8142ab50",
"deprecated": false
}
]
"2026-08-22T09:15:48Z"