CVE-2026-12363 | ZephyrProject Zephyr up to 4.4.x LoRaWAN Fragmented Data Block Transport service frag_transport.c frag_transport_package_callback frag_counter out-of-bounds write

SecurityVulns

A vulnerability has been found in ZephyrProject Zephyr up to 4.4.x and classified as problematic. Affected by this vulnerability is the function frag_transport_package_callback of the file subsys/lorawan/services/frag_transport.c of the component LoRaWAN Fragmented Data Block Transport service. The manipulation of the argument frag_counter leads to out-of-bounds write.

This vulnerability is documented as CVE-2026-12363. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More