---
id: CVE-2026-15893
title: >-
  net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a
  randomized ND reachable time from ipv6->base_reachable_time as min_reachable +
  sys_rand32_get() % (max_reachable - min_reachable), where min_reachable =
  base/2 and max…
summary: >-
  net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a
  randomized ND reachable time from ipv6->base_reachable_time as min_reachable +
  sys_rand32_get() % (max_reachable - min_reachable), where min_reachable =
  base/2 and max…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-617
vendor: zephyrproject
product: zephyr
affected:
  - zephyr >= 1.7.0 < 4.4.2
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:41.650'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15893'
references:
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/commit/251079ed50464aa0976eb0738a5afbe009cc9d60
    label: vulnerabilities@zephyrproject.org
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8v32-9xf8-r765
    label: vulnerabilities@zephyrproject.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T19:02:33.869630Z'
ingestedAt: '2026-09-14T19:13:23.468Z'
epss: 0.002
epssPercentile: 0.10171
---

## Overview

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_reachable = 3*base/2 using integer division. When base_reachable_time is 1, both min_reachable and the modulus collapse so the function returns 0, and net_if_ipv6_set_reachable_time() stores that 0 into ipv6->reachable_time.

The base_reachable_time is attacker-controlled: handle_ra_input() in subsys/net/ip/ipv6_nbr.c accepts the Reachable Time field of an incoming Router Advertisement whenever it is nonzero and <= MAX_REACHABLE_TIME, so a single unauthenticated, link-local RA carrying a Reachable Time of 1 drives the computed reachable time to 0. Router Advertisements are unauthenticated by default and require only adjacency to the target link.

When a neighbor is subsequently confirmed reachable, net_ipv6_nbr_set_reachable_timer() reads the value and executes NET_ASSERT(time, "Zero reachable timeout!"). On builds with CONFIG_ASSERT enabled this triggers a fatal kernel assertion — a remote denial of service; on builds without assertions the reachable timer is armed with K_MSEC(0) and fires immediately, forcing reachable neighbors into perpetual re-solicitation (STALE), degrading Neighbor Discovery. The impact is limited to availability; there is no memory-safety, confidentiality, or integrity consequence.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
