CVE-2026-18415

Source
https://cve.org/CVERecord?id=CVE-2026-18415
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18415.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18415
Aliases
  • GHSA-j76j-jrjc-xgvp
Published
2026-09-28T20:00:01Z
Modified
2026-10-06T07:05:06Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames
Details

ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with CONFIG_NET_L2_IEEE802154_FRAGMENT enabled (the default whenever CONFIG_NET_6LO is set), the branch taken when 6LoWPAN fragmentation is not required performed an unchecked net_buf_add_mem(frame_buf, pkt_buf->data, pkt_buf->len). The only guard was __ASSERT_NO_MSG() inside net_buf_simple_add(), which is compiled out without CONFIG_ASSERT, so an oversized packet silently overran the frame buffer.

The defect is not reachable from the radio: for NET_AF_INET6 packets ieee802154_6lo_encode_pkt() compares the whole packet length against IEEE802154_MTU and takes the fragmentation path when it does not fit, so every buffer copied on the unfragmented branch is within bounds. It is reachable through NET_AF_PACKET sockets bound to an 802.15.4 interface: for NET_SOCK_RAW the 6LoWPAN block is skipped entirely and for NET_SOCK_DGRAM it returns early on the address-family test, leaving no length validation anywhere on the transmit path (net_context_sendto() and net_if_tx() apply none, and pkt_buffer_length() does not clamp the allocation for this L2).

An application — or, in a CONFIG_USERSPACE build, an unprivileged application thread using the zsock_socket()/zsock_sendto() syscalls — can therefore drive a supervisor-mode out-of-bounds write of chosen bytes past the 125-byte pool buffer. With the default CONFIG_NET_BUF_FIXED_DATA_SIZE of 128 bytes the overrun is bounded to roughly ll_hdr_len + 3 bytes; with CONFIG_NET_BUF_VARIABLE_DATA_SIZE a single storage buffer can be as large as CONFIG_NET_PKT_BUF_TX_DATA_POOL_SIZE, making the overrun far larger. The consequence is corruption of memory adjacent to the pool, with a crash or further compromise of kernel state as the practical impact.

The fix validates ll_hdr_len + net_pkt_get_len(pkt) + authtag_len against IEEE802154_MTU before any copy and adds a tailroom-checking copy_pkt_to_frame() helper that returns -EMSGSIZE instead of overrunning the buffer. The same change also linearizes the whole net_buf chain into one MAC frame, so packet storage boundaries no longer become frame boundaries on the wire.

Database specific
{
    "cna_assigner": "zephyr",
    "cwe_ids": [
        "CWE-787"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18415.json"
}
References

Affected packages

Git / github.com/zephyrproject-rtos/zephyr

Affected ranges

Type
GIT
Repo
https://github.com/zephyrproject-rtos/zephyr
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.2.0"
        },
        {
            "fixed": "4.4.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v3.*
v3.2.0
v3.3.0
v3.3.0-rc1
v3.3.0-rc2
v3.3.0-rc3
v3.4.0
v3.4.0-rc1
v3.4.0-rc2
v3.4.0-rc3
v3.5.0
v3.5.0-rc1
v3.5.0-rc2
v3.5.0-rc3
v3.6.0
v3.6.0-rc1
v3.6.0-rc2
v3.6.0-rc3
v3.7.0
v3.7.0-rc1
v3.7.0-rc2
v3.7.0-rc3
v4.*
v4.0.0
v4.0.0-rc1
v4.0.0-rc2
v4.0.0-rc3
v4.1.0
v4.1.0-rc1
v4.1.0-rc2
v4.1.0-rc3
v4.2.0
v4.2.0-rc1
v4.2.0-rc2
v4.2.0-rc3
v4.3.0
v4.3.0-rc1
v4.3.0-rc2
v4.3.0-rc3
v4.4.0
v4.4.0-rc1
v4.4.0-rc2
v4.4.0-rc3
zephyr-v3.*
zephyr-v3.2.0
zephyr-v3.3.0
zephyr-v3.4.0
zephyr-v3.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18415.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "35998828111576063543680040192341427821",
                "318408684839477295078527654397532910225",
                "282829304127560284022315370645265704523",
                "161650606474039353768362371692938466402",
                "19665406416553053096904401528245411142",
                "334114517952867827724432752122631500795",
                "96500699038741406661164279155451505425",
                "267105922697076895239433090255791844909",
                "157187408125877173591411243697537012684",
                "307724017548762753613965937692570061937",
                "94629098439425233743514518159330729486",
                "305577469254794584667537881875151318035",
                "164813136129287923728492665631843492136",
                "243087908459515893518510241967247475285",
                "221597846293788876741830467813350763954",
                "53261274729288141977457509894047517769",
                "6863647581715983911564689280899037027",
                "218143618418618504664131058991736106289",
                "3782406581833511118622192253645882660",
                "207624525697296083124361988563346178821",
                "311384973508603058005781159940605988444",
                "327000114166085443546847991240155801528",
                "257458455602367848596653451554006705016",
                "55158552302994736837943341167030806095",
                "19417525034122747127726690346269388174",
                "33114049283512851411736514449980316836",
                "257277593514473692517868172007190175783",
                "118756439145422528890753867135873509469",
                "78354622888371933055493220313846702816",
                "153858717960651249934860263498427482025",
                "272004816145378916025399497847487552193",
                "126194220932020937909421266572169517005",
                "180449292216934983171095661245254201405",
                "250449033493021607892476748333709209870",
                "337927100299815391796904517371909525830",
                "286797143734770486321017614807853863168",
                "37744841824589739042623369005122770788",
                "274368879540093313231286394092368585485",
                "201282057143853839242501982042233784211",
                "224970301973011663112599910684987182555"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-18415-0276992e",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
        "target": {
            "file": "subsys/net/l2/ieee802154/ieee802154.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "288627365410236786977461492177403879832",
            "length": 2180
        },
        "id": "CVE-2026-18415-03279f96",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
        "target": {
            "file": "subsys/net/l2/ieee802154/ieee802154.c",
            "function": "ieee802154_send"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "38650658734774029729365552367575077722",
                "8954909630579541687509983443467332815",
                "234684897160879052207113039559282909218",
                "232558862762722850773119841934211469189",
                "248707952811877207985533338801667061667",
                "323462012529240562478623998701685884849"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-18415-4036df03",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
        "target": {
            "file": "tests/net/ieee802154/l2/src/ieee802154_test.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "192965892882254605322499614534993211676",
            "length": 2101
        },
        "id": "CVE-2026-18415-b6524f5c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
        "target": {
            "file": "tests/net/ieee802154/6lo_fragment/src/main.c",
            "function": "test_fragment"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "243368102041280108727575991446331782804",
                "106943805651917358519531017385216325731",
                "154815950639538540707738150805421639552",
                "32614088711590999339982392923072617180"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-18415-d4511a39",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
        "target": {
            "file": "tests/net/ieee802154/6lo_fragment/src/main.c"
        }
    }
]
vanir_signatures_modified
"2026-10-06T07:05:06Z"