A high-severity vulnerability, CVE-2026-10673, was disclosed in the Zephyr RTOS ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver, affecting versions 3.7.0 through 4.4.0. The flaw is an out-of-bounds write in OA SPI RX frame reassembly: attacker-controlled 64-byte chunks can be copied into a fixed static buffer without verifying that the write cursor stays within bounds. An attacker on the adjacent single-pair Ethernet segment can send an oversized frame to corrupt memory in the driver's RX offload thread, causing denial of service and potentially enabling code execution.
Zephyr addressed the issue with May 1 patches that add bounds checking and state reset logic when a received packet exceeds CONFIG_ETH_ADIN2111_BUFFER_SIZE, dropping oversized frames and resetting ctx->scur. A related fix also corrected the Open Alliance buffer size calculation from 255 × 64 bytes to 255 × 68 bytes to account for each chunk's 4-byte header in addition to 64 bytes of data. The vulnerability was traced to OA SPI support introduced in commit 0ca8b0756b1, and published scoring indicates CVSS 8.6 with proof-of-concept exploitation status reported in CISA SSVC metadata.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-10673 was published describing an out-of-bounds write in Zephyr RTOS ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly affecting versions 3.7.0 through 4.4.0. The disclosure states that an adjacent attacker can send an oversized frame to cause memory corruption, leading to denial of service and potentially code execution.
Zephyr committed a fix in the ADIN2111 Ethernet driver to prevent writes past the configured buffer during OA SPI frame reassembly. The patch resets state, logs an error, and skips processing when a received frame would exceed the maximum buffer size.
A Zephyr RTOS commit corrected the ADIN2111 Open Alliance buffer size calculation from 255 × 64 bytes to 255 × 68 bytes to account for the 4-byte header in each chunk. The commit was authored and committed on May 1, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.