net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and that neighbor's pending_queue is already non-empty (an NS is already outstanding), the function appends the data packet and returns early without ever sending the NS via net_send_data() or releasing it with net_pkt_unref(). The freshly allocated NS net_pkt and its attached TX buffers are held only by a local variable and are leaked permanently, never returning to CONFIG_NET_PKT_TX_COUNT / CONFIG_NET_BUF_TX_COUNT.
The leaking branch sits on the normal IPv6 transmit path: net_ipv6_prepare_for_send() (called from net_if.c) invokes net_ipv6_send_ns() for any outbound or forwarded IPv6 packet whose next hop is not yet in the neighbor cache. An on-link (adjacent) attacker can drive it deterministically by sending a burst of request packets (for example ICMPv6 echo requests or UDP datagrams) that all spoof a single non-existent on-link source address: the node generates a reply to each, the first reply queues an NS, and every subsequent reply during the roughly three-second INCOMPLETE resolution window takes the leaking branch and loses one TX packet. Router-configured nodes forwarding attacker traffic toward a non-existent on-link host leak identically.
Because the leaked packets are never reclaimed and CONFIG_NET_PKT_TX_COUNT defaults to only 4 (14 for Ethernet), a brief low-rate burst exhausts the TX pool. Once exhausted the node can no longer allocate any transmit packet and cannot send TCP/UDP, ARP/ND, or any reply at all, producing a complete and persistent network denial of service that does not self-heal until reboot. The fix releases the unsent NS packet with net_pkt_unref(pkt) before the early return.
{
"cna_assigner": "zephyr",
"cwe_ids": [
"CWE-401"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14697.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14697.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"298921845268896407730862555920337243635",
"287788309726118340021480113622454908909",
"116718030876046818651160531976525629471",
"237249861522664496586301677128837031409"
],
"threshold": 0.9
},
"id": "CVE-2026-14697-2bbf77e1",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ab2670e8b5b8fcde4a699dd5cbe452abbd233289",
"target": {
"file": "subsys/net/ip/ipv6_nbr.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "217423027088181729818683515660525879222",
"length": 1857
},
"id": "CVE-2026-14697-60d71877",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ab2670e8b5b8fcde4a699dd5cbe452abbd233289",
"target": {
"file": "tests/net/ipv6/src/main.c",
"function": "ZTEST"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "231029484922583101478161412484374543627",
"length": 2778
},
"id": "CVE-2026-14697-83b14182",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ab2670e8b5b8fcde4a699dd5cbe452abbd233289",
"target": {
"file": "subsys/net/ip/ipv6_nbr.c",
"function": "net_ipv6_send_ns"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"22475203157680031688963302249877001970",
"306168646182876113205103678999306470891",
"156231671735986181015453187065785848056",
"69335119360656763635912104959372416680",
"113024277349334555093569652164910894815",
"247104303886515658893759013296606486216"
],
"threshold": 0.9
},
"id": "CVE-2026-14697-ad7d7d75",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/ab2670e8b5b8fcde4a699dd5cbe452abbd233289",
"target": {
"file": "tests/net/ipv6/src/main.c"
}
}
]
"2026-09-03T08:07:08Z"