Home

Description

A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Request. This results in an out-of-bounds memory read and creates a potential information-leak vulnerability in the networking subsystem.

PUBLISHED Reserved 2025-11-07 | Published 2026-01-30 | Updated 2026-01-30 | Assigner zephyr




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Problem types

Access of Resource Using Incompatible Type ('Type Confusion')

Product status

Default status
unaffected

* (git)
affected

References

github.com/...zephyr/security/advisories/GHSA-c2vg-hj83-c2vg

cve.org (CVE-2025-12899)

nvd.nist.gov (CVE-2025-12899)

Download JSON