CVE 6.1 MEDIUM

net: Stack Overflow with Ping (to own IP Address) via Shell_CVE-2026-1681

6.1 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

Description

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local address, both the echo request and the resulting echo reply are processed inline before the current frame returns. The nested input-path frames exceed the work-queue stack and trigger a stack overflow.

Basic Information

ID CVE-2026-1681
Source zephyr
Published May 12, 2026 at 05:39

Affected Product

Vendor zephyrproject-rtos
Product Zephyr
Version *
Affected Versions zephyrproject-rtos Zephyr *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.