CVE-2025-12899: Zephyrproject-Rtos Zephyr
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Request. This results in an out-of-bounds memory read and creates a potential information-leak vulnerability in the networking subsystem.
Affected products
- Zephyrproject-Rtos Zephyr
Published 2026-01-30. Last modified 2026-06-17.