{"id":"CVE-2026-14697","summary":"IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of service","details":"net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and that neighbor's pending_queue is already non-empty (an NS is already outstanding), the function appends the data packet and returns early without ever sending the NS via net_send_data() or releasing it with net_pkt_unref(). The freshly allocated NS net_pkt and its attached TX buffers are held only by a local variable and are leaked permanently, never returning to CONFIG_NET_PKT_TX_COUNT / CONFIG_NET_BUF_TX_COUNT.\n\nThe leaking branch sits on the normal IPv6 transmit path: net_ipv6_prepare_for_send() (called from net_if.c) invokes net_ipv6_send_ns() for any outbound or forwarded IPv6 packet whose next hop is not yet in the neighbor cache. An on-link (adjacent) attacker can drive it deterministically by sending a burst of request packets (for example ICMPv6 echo requests or UDP datagrams) that all spoof a single non-existent on-link source address: the node generates a reply to each, the first reply queues an NS, and every subsequent reply during the roughly three-second INCOMPLETE resolution window takes the leaking branch and loses one TX packet. Router-configured nodes forwarding attacker traffic toward a non-existent on-link host leak identically.\n\nBecause the leaked packets are never reclaimed and CONFIG_NET_PKT_TX_COUNT defaults to only 4 (14 for Ethernet), a brief low-rate burst exhausts the TX pool. Once exhausted the node can no longer allocate any transmit packet and cannot send TCP/UDP, ARP/ND, or any reply at all, producing a complete and persistent network denial of service that does not self-heal until reboot. The fix releases the unsent NS packet with net_pkt_unref(pkt) before the early return.","aliases":["GHSA-x956-p489-8mf5"],"modified":"2026-09-03T08:07:08.865686Z","published":"2026-08-31T19:34:49.586Z","database_specific":{"cna_assigner":"zephyr","cwe_ids":["CWE-401"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14697.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14697.json"},{"type":"ADVISORY","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-x956-p489-8mf5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14697"},{"type":"FIX","url":"https://github.com/zephyrproject-rtos/zephyr/commit/ab2670e8b5b8fcde4a699dd5cbe452abbd233289"},{"type":"PACKAGE","url":"https://github.com/zephyrproject-rtos/zephyr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zephyrproject-rtos/zephyr","events":[{"introduced":"3568e1b6d5cdd51a6b964a2a1d6d29200fea2056"},{"fixed":"ab2670e8b5b8fcde4a699dd5cbe452abbd233289"}],"database_specific":{"extracted_events":[{"introduced":"4.3.0"},{"fixed":"4.4.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v4.4.0","v4.4.0-rc3","v4.4.0-rc2","v4.4.0-rc1","v4.3.0"],"database_specific":{"vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ab2670e8b5b8fcde4a699dd5cbe452abbd233289","target":{"file":"subsys/net/ip/ipv6_nbr.c"},"deprecated":false,"digest":{"line_hashes":["298921845268896407730862555920337243635","287788309726118340021480113622454908909","116718030876046818651160531976525629471","237249861522664496586301677128837031409"],"threshold":0.9},"id":"CVE-2026-14697-2bbf77e1"},{"signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ab2670e8b5b8fcde4a699dd5cbe452abbd233289","target":{"file":"tests/net/ipv6/src/main.c","function":"ZTEST"},"deprecated":false,"digest":{"function_hash":"217423027088181729818683515660525879222","length":1857},"id":"CVE-2026-14697-60d71877","signature_type":"Function"},{"target":{"file":"subsys/net/ip/ipv6_nbr.c","function":"net_ipv6_send_ns"},"deprecated":false,"digest":{"function_hash":"231029484922583101478161412484374543627","length":2778},"id":"CVE-2026-14697-83b14182","signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ab2670e8b5b8fcde4a699dd5cbe452abbd233289"},{"target":{"file":"tests/net/ipv6/src/main.c"},"deprecated":false,"digest":{"line_hashes":["22475203157680031688963302249877001970","306168646182876113205103678999306470891","156231671735986181015453187065785848056","69335119360656763635912104959372416680","113024277349334555093569652164910894815","247104303886515658893759013296606486216"],"threshold":0.9},"id":"CVE-2026-14697-ad7d7d75","signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/ab2670e8b5b8fcde4a699dd5cbe452abbd233289"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14697.json","vanir_signatures_modified":"2026-09-03T08:07:08Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}