{"id":"CVE-2026-18415","summary":"Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames","details":"ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte transmit buffer (tx_frame_buf_pool, sized IEEE802154_MTU). In builds with CONFIG_NET_L2_IEEE802154_FRAGMENT enabled (the default whenever CONFIG_NET_6LO is set), the branch taken when 6LoWPAN fragmentation is not required performed an unchecked net_buf_add_mem(frame_buf, pkt_buf-\u003edata, pkt_buf-\u003elen). The only guard was __ASSERT_NO_MSG() inside net_buf_simple_add(), which is compiled out without CONFIG_ASSERT, so an oversized packet silently overran the frame buffer.\n\nThe defect is not reachable from the radio: for NET_AF_INET6 packets ieee802154_6lo_encode_pkt() compares the whole packet length against IEEE802154_MTU and takes the fragmentation path when it does not fit, so every buffer copied on the unfragmented branch is within bounds. It is reachable through NET_AF_PACKET sockets bound to an 802.15.4 interface: for NET_SOCK_RAW the 6LoWPAN block is skipped entirely and for NET_SOCK_DGRAM it returns early on the address-family test, leaving no length validation anywhere on the transmit path (net_context_sendto() and net_if_tx() apply none, and pkt_buffer_length() does not clamp the allocation for this L2).\n\nAn application — or, in a CONFIG_USERSPACE build, an unprivileged application thread using the zsock_socket()/zsock_sendto() syscalls — can therefore drive a supervisor-mode out-of-bounds write of chosen bytes past the 125-byte pool buffer. With the default CONFIG_NET_BUF_FIXED_DATA_SIZE of 128 bytes the overrun is bounded to roughly ll_hdr_len + 3 bytes; with CONFIG_NET_BUF_VARIABLE_DATA_SIZE a single storage buffer can be as large as CONFIG_NET_PKT_BUF_TX_DATA_POOL_SIZE, making the overrun far larger. The consequence is corruption of memory adjacent to the pool, with a crash or further compromise of kernel state as the practical impact.\n\nThe fix validates ll_hdr_len + net_pkt_get_len(pkt) + authtag_len against IEEE802154_MTU before any copy and adds a tailroom-checking copy_pkt_to_frame() helper that returns -EMSGSIZE instead of overrunning the buffer. The same change also linearizes the whole net_buf chain into one MAC frame, so packet storage boundaries no longer become frame boundaries on the wire.","aliases":["GHSA-j76j-jrjc-xgvp"],"modified":"2026-10-06T07:05:06.597366Z","published":"2026-09-28T20:00:01.312Z","database_specific":{"cna_assigner":"zephyr","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18415.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18415.json"},{"type":"ADVISORY","url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j76j-jrjc-xgvp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18415"},{"type":"FIX","url":"https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227"},{"type":"PACKAGE","url":"https://github.com/zephyrproject-rtos/zephyr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zephyrproject-rtos/zephyr","events":[{"introduced":"4256cd41df6c60f1832fd2deb14edc30ac7debab"},{"fixed":"3d4c6177d2dbd77d12d9b14cd75a00cdbd826227"}],"database_specific":{"extracted_events":[{"introduced":"3.2.0"},{"fixed":"4.4.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v4.4.0","v4.4.0-rc3","v4.4.0-rc2","v4.4.0-rc1","v4.3.0","v4.3.0-rc3","v4.3.0-rc2","v4.3.0-rc1","v4.2.0","v4.2.0-rc3","v4.2.0-rc2","v4.2.0-rc1","v4.1.0","v4.1.0-rc3","v4.1.0-rc2","v4.1.0-rc1","v4.0.0","v4.0.0-rc3","v4.0.0-rc2","v4.0.0-rc1","v3.7.0","v3.7.0-rc3","v3.7.0-rc2","v3.7.0-rc1","v3.6.0","v3.6.0-rc3","v3.6.0-rc2","v3.6.0-rc1","zephyr-v3.5.0","v3.5.0","v3.5.0-rc3","v3.5.0-rc2","v3.5.0-rc1","zephyr-v3.4.0","v3.4.0","v3.4.0-rc3","v3.4.0-rc2","v3.4.0-rc1","zephyr-v3.3.0","v3.3.0","v3.3.0-rc3","v3.3.0-rc2","v3.3.0-rc1","zephyr-v3.2.0","v3.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18415.json","vanir_signatures_modified":"2026-10-06T07:05:06Z","vanir_signatures":[{"source":"https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227","target":{"file":"subsys/net/l2/ieee802154/ieee802154.c"},"deprecated":false,"digest":{"line_hashes":["35998828111576063543680040192341427821","318408684839477295078527654397532910225","282829304127560284022315370645265704523","161650606474039353768362371692938466402","19665406416553053096904401528245411142","334114517952867827724432752122631500795","96500699038741406661164279155451505425","267105922697076895239433090255791844909","157187408125877173591411243697537012684","307724017548762753613965937692570061937","94629098439425233743514518159330729486","305577469254794584667537881875151318035","164813136129287923728492665631843492136","243087908459515893518510241967247475285","221597846293788876741830467813350763954","53261274729288141977457509894047517769","6863647581715983911564689280899037027","218143618418618504664131058991736106289","3782406581833511118622192253645882660","207624525697296083124361988563346178821","311384973508603058005781159940605988444","327000114166085443546847991240155801528","257458455602367848596653451554006705016","55158552302994736837943341167030806095","19417525034122747127726690346269388174","33114049283512851411736514449980316836","257277593514473692517868172007190175783","118756439145422528890753867135873509469","78354622888371933055493220313846702816","153858717960651249934860263498427482025","272004816145378916025399497847487552193","126194220932020937909421266572169517005","180449292216934983171095661245254201405","250449033493021607892476748333709209870","337927100299815391796904517371909525830","286797143734770486321017614807853863168","37744841824589739042623369005122770788","274368879540093313231286394092368585485","201282057143853839242501982042233784211","224970301973011663112599910684987182555"],"threshold":0.9},"id":"CVE-2026-18415-0276992e","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227","target":{"file":"subsys/net/l2/ieee802154/ieee802154.c","function":"ieee802154_send"},"deprecated":false,"digest":{"function_hash":"288627365410236786977461492177403879832","length":2180},"id":"CVE-2026-18415-03279f96"},{"digest":{"line_hashes":["38650658734774029729365552367575077722","8954909630579541687509983443467332815","234684897160879052207113039559282909218","232558862762722850773119841934211469189","248707952811877207985533338801667061667","323462012529240562478623998701685884849"],"threshold":0.9},"id":"CVE-2026-18415-4036df03","signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227","target":{"file":"tests/net/ieee802154/l2/src/ieee802154_test.c"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227","target":{"function":"test_fragment","file":"tests/net/ieee802154/6lo_fragment/src/main.c"},"deprecated":false,"digest":{"function_hash":"192965892882254605322499614534993211676","length":2101},"id":"CVE-2026-18415-b6524f5c","signature_type":"Function"},{"target":{"file":"tests/net/ieee802154/6lo_fragment/src/main.c"},"deprecated":false,"digest":{"line_hashes":["243368102041280108727575991446331782804","106943805651917358519531017385216325731","154815950639538540707738150805421639552","32614088711590999339982392923072617180"],"threshold":0.9},"id":"CVE-2026-18415-d4511a39","signature_type":"Line","signature_version":"v1","source":"https://github.com/zephyrproject-rtos/zephyr/commit/3d4c6177d2dbd77d12d9b14cd75a00cdbd826227"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}