---
id: CVE-2026-16514
title: >-
  gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the
  Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each
  clock identity against the local one
summary: >-
  gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the
  Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each
  clock identity against the local one. The loop bound was taken solely from the
  attac…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-125
vendor: zephyrproject
product: zephyr
affected:
  - zephyr >= 1.13.0 < 4.4.2
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:11:57.760'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16514'
references:
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/commit/a2c882db7a57cf08a06b4d27bead22b07a9c3c61
    label: vulnerabilities@zephyrproject.org
  - url: >-
      https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-mgxg-89rr-6855
    label: vulnerabilities@zephyrproject.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T16:41:50.328879Z'
ingestedAt: '2026-09-18T14:43:13.064Z'
epss: 0.00238
epssPercentile: 0.13209
---

## Overview

gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken solely from the attacker-controlled wire field announce->steps_removed (accepted up to 254), never from announce->tlv.len, which is the field that states how many identities the TLV actually carries. Because path_sequence is the flexible member of the wire TLV (struct gptp_path_trace_tlv) and GPTP_ANNOUNCE() yields a raw pointer into the received packet buffer, the memcmp() inside the loop can address memory well past the end of the received frame.

The stack's only length validation, GPTP_ANNOUNCE_CHECK_LEN(), requires the received gPTP payload to be exactly 68 + tlv.len bytes — so it does not constrain the loop, it guarantees the data is absent. An unauthenticated attacker on the same Ethernet segment can send a single Announce frame declaring tlv.len = 0 with steps_removed = 254; the frame passes the length check and reception path (net_gptp_recv() → gptp_handle_msg() → gptp_mi_qualify_announce()), which performs no authentication, and the loop then reads 255 entries of 8 bytes each — about 2 KB — beyond the end of the network buffer.

The impact is an out-of-bounds read. The bytes read are only used as a memcmp() operand and are never returned to the attacker, so there is no meaningful information disclosure; the practical risk is that the overread crosses a network buffer pool boundary into unmapped or MPU-protected memory and faults the networking RX thread, causing a denial of service. Exposure is limited to builds that enable the opt-in, experimental CONFIG_NET_GPTP (TSN/AVB deployments) and to attackers with layer-2 adjacency, since gPTP frames are sent to a link-local multicast address and are not routed.

The fix computes the true entry count as tlv.len / GPTP_CLOCK_ID_LEN and rejects the announce when steps_removed + 1 exceeds it, so the loop can no longer run past the data the packet-length check proved present.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
