Type ConfusionWeakness · CWE-843

CVE-2025-12899

MEDIUM · 6.5 CVSS v3.1 Published 2026-01-30
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
74/100
Remediation priority · Elevated
Remotely reachable No privileges Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
A flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Request. This results in an out-of-bounds memory read and creates a potential information-leak vulnerability in the networking subsystem.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · moderate confidence

Zephyr's network stack incorrectly handles IPv4 packets with ICMP type 128 (Echo Request), misclassifying them as ICMPv6 Echo Request packets. This classification error causes the packet processing logic to use incorrect parsing assumptions, resulting in an out-of-bounds memory read that can leak sensitive information from the networking subsystem's memory space.

MitigationApply the Zephyr project patches for CVE-2025-12899 which add proper IP version verification before ICMP type interpretation and implement correct bounds checking in the ICMP packet handling code.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Confirm Zephyr RTOS usage
    Identify if the target system runs Zephyr by checking build configuration files, kernel image metadata, or system documentation. Look for Zephyr-specific paths or build artifacts.
    Affected if The system does not use Zephyr RTOS - this CVE only applies to Zephyr-based systems.
  2. Determine Zephyr version
    Check the Zephyr kernel or library version string in the deployed firmware/image. Compare against the affected version range provided in CVE-2025-12899 advisory.
    Affected if The installed Zephyr version falls within the affected range and has not been patched.
  3. Verify IPv4 network stack is enabled
    Examine the Zephyr network configuration (typically in prj.conf or Kconfig) for CONFIG_NET_IPV4=y setting, which enables IPv4 packet processing.
    Affected if IPv4 support is enabled - the vulnerability lies in IPv4 packet handling misclassification.
  4. Check ICMP echo request handling is active
    Inspect network stack configuration for CONFIG_NET_ICMP=y and related ICMP echo request settings. Verify the device processes ICMP echo requests.
    Affected if ICMP echo request processing is enabled - the flaw triggers when IPv4 ICMP type 128 packets are received.
  5. Inspect packet classification code path
    Review network subsystem logs or code if accessible: verify whether incoming IPv4 ICMP packets are being parsed through ICMPv6 handling routines. Check for anomalies in packet processing flow.
    Affected if IPv4 ICMP packets are incorrectly routed to ICMPv6 parsing logic - this indicates the vulnerability is present.

A system is affected if it runs a vulnerable Zephyr version with IPv4 and ICMP echo request processing enabled, where IPv4 ICMP type 128 packets are incorrectly classified as ICMPv6 echo requests.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

From vendor data
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

Apply the Zephyr project patches for CVE-2025-12899 which add proper IP version verification before ICMP type interpretation and implement correct bounds checking in the ICMP packet handling code.

Have this fixed Scoped from the published advisory
  • Consultation4.0 h
  • Implementation8.0 h
  • Testing8.0 h
  • Review / QA4.0 h
24.0 hours of engineering $4,160
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $6,656.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2025-12899 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2025-12899 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data