ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with CONFIG_NET_L2_IEEE802154_FRAGMENT enabled (the default whenever CONFIG_NET_6LO is set), the branch taken when 6LoWPAN fragmentation is not required performed an unchecked net_buf_add_mem(frame_buf, pkt_buf->data, pkt_buf->len). The only guard was __ASSERT_NO_MSG() inside net_buf_simple_add(), which is compiled out without CONFIG_ASSERT, so an oversized packet silently overran the frame buffer.
The defect is not reachable from the radio: for NET_AF_INET6 packets ieee802154_6lo_encode_pkt() compares the whole packet length against IEEE802154_MTU and takes the fragmentation path when it does not fit, so every buffer copied on the unfragmented branch is within bounds. It is reachable through NET_AF_PACKET sockets bound to an 802.15.4 interface: for NET_SOCK_RAW the 6LoWPAN block is skipped entirely and for NET_SOCK_DGRAM it returns early on the address-family test, leaving no length validation anywhere on the transmit path (net_context_sendto() and net_if_tx() apply none, and pkt_buffer_length() does not clamp the allocation for this L2).
An application — or, in a CONFIG_USERSPACE build, an unprivileged application thread using the zsock_socket()/zsock_sendto() syscalls — can therefore drive a supervisor-mode out-of-bounds write of chosen bytes past the 125-byte pool buffer. With the default CONFIG_NET_BUF_FIXED_DATA_SIZE of 128 bytes the overrun is bounded to roughly ll_hdr_len + 3 bytes; with CONFIG_NET_BUF_VARIABLE_DATA_SIZE a single storage buffer can be as large as CONFIG_NET_PKT_BUF_TX_DATA_POOL_SIZE, making the overrun far larger. The consequence is corruption of memory adjacent to the pool, with a crash or further compromise of kernel state as the practical impact.
The fix validates ll_hdr_len + net_pkt_get_len(pkt) + authtag_len against IEEE802154_MTU before any copy and adds a tailroom-checking copy_pkt_to_frame() helper that returns -EMSGSIZE instead of overrunning the buffer. The same change also linearizes the whole net_buf chain into one MAC frame, so packet storage boundaries no longer become frame boundaries on the wire.
{
"cna_assigner": "zephyr",
"cwe_ids": [
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18415.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18415.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"35998828111576063543680040192341427821",
"318408684839477295078527654397532910225",
"282829304127560284022315370645265704523",
"161650606474039353768362371692938466402",
"19665406416553053096904401528245411142",
"334114517952867827724432752122631500795",
"96500699038741406661164279155451505425",
"267105922697076895239433090255791844909",
"157187408125877173591411243697537012684",
"307724017548762753613965937692570061937",
"94629098439425233743514518159330729486",
"305577469254794584667537881875151318035",
"164813136129287923728492665631843492136",
"243087908459515893518510241967247475285",
"221597846293788876741830467813350763954",
"53261274729288141977457509894047517769",
"6863647581715983911564689280899037027",
"218143618418618504664131058991736106289",
"3782406581833511118622192253645882660",
"207624525697296083124361988563346178821",
"311384973508603058005781159940605988444",
"327000114166085443546847991240155801528",
"257458455602367848596653451554006705016",
"55158552302994736837943341167030806095",
"19417525034122747127726690346269388174",
"33114049283512851411736514449980316836",
"257277593514473692517868172007190175783",
"118756439145422528890753867135873509469",
"78354622888371933055493220313846702816",
"153858717960651249934860263498427482025",
"272004816145378916025399497847487552193",
"126194220932020937909421266572169517005",
"180449292216934983171095661245254201405",
"250449033493021607892476748333709209870",
"337927100299815391796904517371909525830",
"286797143734770486321017614807853863168",
"37744841824589739042623369005122770788",
"274368879540093313231286394092368585485",
"201282057143853839242501982042233784211",
"224970301973011663112599910684987182555"
],
"threshold": 0.9
},
"id": "CVE-2026-18415-0276992e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
"target": {
"file": "subsys/net/l2/ieee802154/ieee802154.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "288627365410236786977461492177403879832",
"length": 2180
},
"id": "CVE-2026-18415-03279f96",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
"target": {
"file": "subsys/net/l2/ieee802154/ieee802154.c",
"function": "ieee802154_send"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"38650658734774029729365552367575077722",
"8954909630579541687509983443467332815",
"234684897160879052207113039559282909218",
"232558862762722850773119841934211469189",
"248707952811877207985533338801667061667",
"323462012529240562478623998701685884849"
],
"threshold": 0.9
},
"id": "CVE-2026-18415-4036df03",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
"target": {
"file": "tests/net/ieee802154/l2/src/ieee802154_test.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "192965892882254605322499614534993211676",
"length": 2101
},
"id": "CVE-2026-18415-b6524f5c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
"target": {
"file": "tests/net/ieee802154/6lo_fragment/src/main.c",
"function": "test_fragment"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"243368102041280108727575991446331782804",
"106943805651917358519531017385216325731",
"154815950639538540707738150805421639552",
"32614088711590999339982392923072617180"
],
"threshold": 0.9
},
"id": "CVE-2026-18415-d4511a39",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227",
"target": {
"file": "tests/net/ieee802154/6lo_fragment/src/main.c"
}
}
]
"2026-10-06T07:05:06Z"