Home

Description

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local address, both the echo request and the resulting echo reply are processed inline before the current frame returns. The nested input-path frames exceed the work-queue stack and trigger a stack overflow.

PUBLISHED Reserved 2026-01-30 | Published 2026-05-12 | Updated 2026-05-12 | Assigner zephyr




MEDIUM: 6.1CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

Problem types

Uncontrolled Recursion

Product status

Default status
unaffected

* (git)
affected

References

github.com/...zephyr/security/advisories/GHSA-6fcc-8rwr-w7xx

cve.org (CVE-2026-1681)

nvd.nist.gov (CVE-2026-1681)

Download JSON