{"id":"CVE-2026-12522","summary":"Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fields","details":"The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800.c parses the PDP-context dynamic parameters (local address, subnet mask, gateway, and DNS servers) that the cellular network assigns to the device. The response is linearized into a 256-byte stack buffer, after which each address field length is computed from comma/. delimiter positions in the network-supplied data and used directly as the length argument to strncpy() into the fixed 64-byte stack buffer temp_addr_str (and the 16-byte iface_ctx.dns_v4_string).\n\nBecause the field length is derived from attacker-controlled delimiter positions and was not bounded against the destination buffer, a single field can be far larger than 64 bytes. A malicious or impersonated cellular network (for example a rogue base station) can return a crafted +CGCONTRDP response with an overlong address field, causing strncpy() to write past temp_addr_str on the modem worker thread's stack, plus an out-of-bounds NUL write at temp_addr_str[addr_len].\n\nNo device-side privileges or user interaction are required: the device itself issues the AT+CGCONTRDP=1 query during normal network attach and parses whatever the network returns. The overflow corrupts adjacent stack memory in supervisor context, yielding at minimum a remotely triggerable crash and potentially control-flow hijacking on targets without stack protection.\n\nThe fix bounds every field length against its destination buffer (temp_addr_str and dns_v4_string) before each copy, rejecting overlong fields.","aliases":["GHSA-hchc-6489-w66v"],"modified":"2026-08-22T09:15:47.346826Z","published":"2026-08-19T20:37:35.638Z","database_specific":{"cna_assigner":"zephyr","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12522.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12522.json"},{"type":"ADVISORY","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hchc-6489-w66v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12522"},{"type":"FIX","url":"https://github.com/zephyrproject-rtos/zephyr/commit/a1cbced64181bc0bdf95e1fd7118f2bb70cf679b"},{"type":"PACKAGE","url":"https://github.com/zephyrproject-rtos/zephyr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zephyrproject-rtos/zephyr","events":[{"introduced":"7a3b253ced7333f5c0269387a7f3ed1dee69739d"},{"fixed":"a1cbced64181bc0bdf95e1fd7118f2bb70cf679b"}],"database_specific":{"extracted_events":[{"introduced":"2.4.0"},{"fixed":"4.4.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v4.4.0","v4.4.0-rc3","v4.4.0-rc2","v4.4.0-rc1","v4.3.0","v4.3.0-rc3","v4.3.0-rc2","v4.3.0-rc1","v4.2.0","v4.2.0-rc3","v4.2.0-rc2","v4.2.0-rc1","v4.1.0","v4.1.0-rc3","v4.1.0-rc2","v4.1.0-rc1","v4.0.0","v4.0.0-rc3","v4.0.0-rc2","v4.0.0-rc1","v3.7.0","v3.7.0-rc3","v3.7.0-rc2","v3.7.0-rc1","v3.6.0","v3.6.0-rc3","v3.6.0-rc2","v3.6.0-rc1","zephyr-v3.5.0","v3.5.0","v3.5.0-rc3","v3.5.0-rc2","v3.5.0-rc1","zephyr-v3.4.0","v3.4.0","v3.4.0-rc3","v3.4.0-rc2","v3.4.0-rc1","zephyr-v3.3.0","v3.3.0","v3.3.0-rc3","v3.3.0-rc2","v3.3.0-rc1","zephyr-v3.2.0","v3.2.0","v3.2.0-rc3","v3.2.0-rc2","v3.2.0-rc1","zephyr-v3.1.0","v3.1.0","v3.1.0-rc3","v3.1.0-rc2","v3.1.0-rc1","zephyr-v3.0.0","v3.0.0","v3.0.0-rc3","v3.0.0-rc2","v3.0.0-rc1","v2.7.99","v2.7.0-rc3","v2.7.0-rc2","v2.7.0-rc1","zephyr-v2.6.0","v2.6.0","v2.6.0-rc3","v2.6.0-rc2","v2.6.0-rc1","zephyr-v2.5.0","v2.5.0","v2.5.0-rc4","v2.5.0-rc3","v2.5.0-rc2","v2.5.0-rc1","zephyr-v2.4.0","v2.4.0"],"database_specific":{"vanir_signatures_modified":"2026-08-22T09:15:47Z","vanir_signatures":[{"id":"CVE-2026-12522-7adf10f0","signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/a1cbced64181bc0bdf95e1fd7118f2bb70cf679b","target":{"file":"drivers/modem/vendor_standalone/hl7800.c"},"deprecated":false,"digest":{"line_hashes":["287891819386438392889812238334022337693","26985787934506337940489959131572696176","105930578250863363515222963532695466391","234911816821555513059205440965024654189","217769298244003326511683035072526765610","108770502343956227854663701894465780599","192322761629158937202580547074163534268","141979584196346062493506464886838430188","138660747348214218667709771249452421197","200027472502609712781721863461679221991","12344556396077867669103365967984211218","82656068111220114540600709545253241303","22692281620249225950835737069933556765","47569026134929437747629728394436990165","147038488551912803958283973106339800883","124309366356269732082956642654587854879","227753519498823534994057299903456220034","294560589674269039180469439425250515784","248456359851319964648222024932286515462"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"272667793880744497670007174777949949677","length":3630},"id":"CVE-2026-12522-d96aa498","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/a1cbced64181bc0bdf95e1fd7118f2bb70cf679b","target":{"function":"on_cmd_atcmdinfo_ipaddr","file":"drivers/modem/vendor_standalone/hl7800.c"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12522.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}