CVE-2026-16514 | ZephyrProject Zephyr up to 4.4.1 gPTP gptp_mi.c gptp_mi_qualify_announce steps_removed out-of-bounds

SecurityVulns

A vulnerability classified as critical has been found in ZephyrProject Zephyr up to 4.4.1. This affects the function gptp_mi_qualify_announce of the file subsys/net/l2/ethernet/gptp/gptp_mi.c of the component gPTP. The manipulation of the argument steps_removed leads to out-of-bounds read.

This vulnerability is referenced as CVE-2026-16514. Remote exploitation of the attack is possible. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More