CVE-2026-1681: falha de média gravidade em zephyrproject-rtos Zephyr
net: Stack Overflow with Ping (to own IP Address) via Shell
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.1epss 0.1%
probabilidade de exploração
0.1%top 97% das CVEs
exploração observada
nãonenhuma fonte reporta
Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local address, both the echo request and the resulting echo reply are processed inline before the current frame returns. The nested input-path frames exceed the work-queue stack and trigger a stack overflow.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Produtos afetados
zephyrproject-rtos · ZephyrCVEs relacionadas — zephyrproject-rtos Zephyr
No mesmo produto, das mais perigosas para as menos.
CVE-2023-3725HIGHPotential buffer overflow vulnerability in the Zephyr CANbus subsystemEPSS 1.3%CVE-2023-4264HIGHPotential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystemEPSS 1.1%CVE-2023-0359MEDIUMipv6: Missing ipv6 nullptr-check in handle_ra_inputEPSS 0.9%CVE-2023-4257HIGHUnchecked user input length in the Zephyr WiFi shell moduleEPSS 0.9%CVE-2023-5753MEDIUMPotential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystemEPSS 0.9%CVE-2023-4260MEDIUMPotential off-by-one buffer overflow vulnerability in the Zephyr FS subsystemEPSS 0.9%