CVE-2026-12363: bounds in zephyrproject zephyr
The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does not validate the fragment counter in a received DATA_FRAGMENT command before forwarding it to the configured decoder. In frag_transport_package_callback() the value frag_counter = hdr->frag_index_n & 0x3FFF is taken directly from the downlink payload and passed to the decoder, which derives an array index and flash offset as frag_counter - 1. DataFragment fragments are 1-indexed, so a frag_counter of 0 underflows that arithmetic. With the default Semtech/LoRaMAC-node decoder, this reaches FragDecoder.FragNbMissingIndex[fragCounter - 1] = 0; in FragDecoderProcess(), where fragCounter - 1 evaluates to -1 and writes a uint16_t zero out of bounds, just before the array and into the adjacent MatrixM2B recovery-matrix state of the static decoder object (CWE-787). A companion write derives a wild flash offset, but that path is rejected by the flash_area_write() bounds check. The in-tree low-memory decoder (frag_dec()) is not corrupted: its out-of-range bit-array and flash accesses are caught by sys_bitarray_ and flash_area_ bounds checks. The handler is the registered downlink callback for the fragmentation transport port, reachable whenever an active fragmentation session exists, so the triggering byte is attacker-influenceable LoRaWAN/FUOTA network input. Triggering it requires authenticated downlinks (LoRaWAN MAC session keys or a malicious/compromised network or FUOTA server) and an active fragmentation session. The impact is contained: corruption of decoder state and denial of the firmware-update (FUOTA) session rather than controllable memory corruption or code execution. The fix adds a transport-layer check that rejects frag_counter == 0, closing the defect for both decoder backends.
AI Analysis
Technical Summary
The LoRaWAN Fragmented Data Block Transport service in Zephyr does not validate the fragment counter in a received DATA_FRAGMENT command before forwarding it to the decoder. Specifically, a frag_counter value of zero causes an underflow in array indexing, leading to an out-of-bounds write of a uint16_t zero into the adjacent recovery matrix state of the decoder object. This vulnerability requires authenticated downlink access and an active fragmentation session. The impact is limited to corruption of decoder state and denial of the firmware update session (FUOTA), without controllable memory corruption or code execution. The fix adds a transport-layer check rejecting frag_counter == 0, mitigating the issue for both decoder backends.
Potential Impact
An attacker with authenticated downlink access to an active fragmentation session can trigger out-of-bounds writes in the decoder state, causing corruption and denial of the firmware update session. There is no impact on confidentiality or integrity beyond denial of service, and no known exploit for arbitrary code execution. The vulnerability affects availability of the FUOTA process.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor has implemented a fix that adds a transport-layer check rejecting frag_counter values of zero, closing the defect for both decoder backends. Until the fix is applied, ensure that only trusted and authenticated downlink sources can send fragmentation commands.
CVE-2026-12363: bounds in zephyrproject zephyr
Description
The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does not validate the fragment counter in a received DATA_FRAGMENT command before forwarding it to the configured decoder. In frag_transport_package_callback() the value frag_counter = hdr->frag_index_n & 0x3FFF is taken directly from the downlink payload and passed to the decoder, which derives an array index and flash offset as frag_counter - 1. DataFragment fragments are 1-indexed, so a frag_counter of 0 underflows that arithmetic. With the default Semtech/LoRaMAC-node decoder, this reaches FragDecoder.FragNbMissingIndex[fragCounter - 1] = 0; in FragDecoderProcess(), where fragCounter - 1 evaluates to -1 and writes a uint16_t zero out of bounds, just before the array and into the adjacent MatrixM2B recovery-matrix state of the static decoder object (CWE-787). A companion write derives a wild flash offset, but that path is rejected by the flash_area_write() bounds check. The in-tree low-memory decoder (frag_dec()) is not corrupted: its out-of-range bit-array and flash accesses are caught by sys_bitarray_ and flash_area_ bounds checks. The handler is the registered downlink callback for the fragmentation transport port, reachable whenever an active fragmentation session exists, so the triggering byte is attacker-influenceable LoRaWAN/FUOTA network input. Triggering it requires authenticated downlinks (LoRaWAN MAC session keys or a malicious/compromised network or FUOTA server) and an active fragmentation session. The impact is contained: corruption of decoder state and denial of the firmware-update (FUOTA) session rather than controllable memory corruption or code execution. The fix adds a transport-layer check that rejects frag_counter == 0, closing the defect for both decoder backends.
CVSS v3.1
Score 4.2medium
Affected software
zephyrproject
zephyr
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The LoRaWAN Fragmented Data Block Transport service in Zephyr does not validate the fragment counter in a received DATA_FRAGMENT command before forwarding it to the decoder. Specifically, a frag_counter value of zero causes an underflow in array indexing, leading to an out-of-bounds write of a uint16_t zero into the adjacent recovery matrix state of the decoder object. This vulnerability requires authenticated downlink access and an active fragmentation session. The impact is limited to corruption of decoder state and denial of the firmware update session (FUOTA), without controllable memory corruption or code execution. The fix adds a transport-layer check rejecting frag_counter == 0, mitigating the issue for both decoder backends.
Potential Impact
An attacker with authenticated downlink access to an active fragmentation session can trigger out-of-bounds writes in the decoder state, causing corruption and denial of the firmware update session. There is no impact on confidentiality or integrity beyond denial of service, and no known exploit for arbitrary code execution. The vulnerability affects availability of the FUOTA process.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vendor has implemented a fix that adds a transport-layer check rejecting frag_counter values of zero, closing the defect for both decoder backends. Until the fix is applied, ensure that only trusted and authenticated downlink sources can send fragmentation commands.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- zephyr
- Date Reserved
- 2026-06-16T03:53:41.904Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7f5a78bf8831d539821039
Added to database: 08/14/2026, 18:12:08 UTC
Last enriched: 08/14/2026, 18:29:27 UTC
Last updated: 09/27/2026, 01:47:40 UTC
Views: 59
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.