CVE-2025-12899

A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Request. This results in an out-of-bounds memory read and creates a potential information-leak vulnerability in the networking subsystem.
Configurations

No configuration.

History

04 Feb 2026, 16:34

Type Values Removed Values Added
Summary
  • (es) Un fallo en la pila de red de Zephyr permite que un paquete IPv4 que contiene ICMP tipo 128 sea clasificado erróneamente como una solicitud de eco ICMPv6. Esto resulta en una lectura de memoria fuera de límites y crea una potencial vulnerabilidad de fuga de información en el subsistema de red.

30 Jan 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 06:16

Updated : 2026-02-04 16:34


NVD link : CVE-2025-12899

Mitre link : CVE-2025-12899

CVE.ORG link : CVE-2025-12899


JSON object : View

Products Affected

No product.

CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')