CVE-2025-12899
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedA flaw in Zephyr’s network stack allows an IPv4 packet containing ICMP type 128 to be misclassified as an ICMPv6 Echo Request. This results in an out-of-bounds memory read and creates a potential information-leak vulnerability in the networking subsystem.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · moderate confidenceZephyr's network stack incorrectly handles IPv4 packets with ICMP type 128 (Echo Request), misclassifying them as ICMPv6 Echo Request packets. This classification error causes the packet processing logic to use incorrect parsing assumptions, resulting in an out-of-bounds memory read that can leak sensitive information from the networking subsystem's memory space.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- Low
- Integrity
- None
- Availability
- Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Confirm Zephyr RTOS usageIdentify if the target system runs Zephyr by checking build configuration files, kernel image metadata, or system documentation. Look for Zephyr-specific paths or build artifacts.Affected if The system does not use Zephyr RTOS - this CVE only applies to Zephyr-based systems.
-
Determine Zephyr versionCheck the Zephyr kernel or library version string in the deployed firmware/image. Compare against the affected version range provided in CVE-2025-12899 advisory.Affected if The installed Zephyr version falls within the affected range and has not been patched.
-
Verify IPv4 network stack is enabledExamine the Zephyr network configuration (typically in prj.conf or Kconfig) for CONFIG_NET_IPV4=y setting, which enables IPv4 packet processing.Affected if IPv4 support is enabled - the vulnerability lies in IPv4 packet handling misclassification.
-
Check ICMP echo request handling is activeInspect network stack configuration for CONFIG_NET_ICMP=y and related ICMP echo request settings. Verify the device processes ICMP echo requests.Affected if ICMP echo request processing is enabled - the flaw triggers when IPv4 ICMP type 128 packets are received.
-
Inspect packet classification code pathReview network subsystem logs or code if accessible: verify whether incoming IPv4 ICMP packets are being parsed through ICMPv6 handling routines. Check for anomalies in packet processing flow.Affected if IPv4 ICMP packets are incorrectly routed to ICMPv6 parsing logic - this indicates the vulnerability is present.
A system is affected if it runs a vulnerable Zephyr version with IPv4 and ICMP echo request processing enabled, where IPv4 ICMP type 128 packets are incorrectly classified as ICMPv6 echo requests.
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
From vendor dataApply the Zephyr project patches for CVE-2025-12899 which add proper IP version verification before ICMP type interpretation and implement correct bounds checking in the ICMP packet handling code.
- Consultation4.0 h
- Implementation8.0 h
- Testing8.0 h
- Review / QA4.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $6,656.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2025-12899 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2025-12899 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data