← Browse

Zephyrproject

49 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-10674 MEDIUM 5.5 Zephyr — The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is en… 2026-07-21 CVE-2026-10675 MEDIUM 4.3 Zephyr — In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() resche… 2026-07-21 CVE-2026-10677 MEDIUM 6.5 Zephyr — The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the use… 2026-07-21 CVE-2026-10678 HIGH 8.1 Zephyr — The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-reg… 2026-07-21 CVE-2026-10679 LOW 3.3 Zephyr — The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency… 2026-07-21 CVE-2026-10680 HIGH 7.6 Zephyr — The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/… 2026-07-21 CVE-2026-10673 HIGH 8.3 Zephyr — The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles rece…● PoC 2026-07-15 CVE-2026-10669 HIGH 7.8 Zephyr — On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/m… 2026-07-14 CVE-2026-10670 MEDIUM 5.5 Zephyr — The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy(… 2026-07-14 CVE-2026-10671 HIGH 7.1 Zephyr — In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c u… 2026-07-14 CVE-2026-10672 HIGH 8.2 Zephyr — subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (c…● PoC 2026-07-14 CVE-2026-10663 MEDIUM 6.1 Zephyr — In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usb… 2026-07-12 CVE-2026-10664 MEDIUM 5 Zephyr — The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nr…● PoC 2026-07-12 CVE-2026-10665 HIGH 7.4 Zephyr — In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearize…● PoC 2026-07-12 CVE-2026-10666 HIGH 8.1 Zephyr — parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") …● PoC 2026-07-12 CVE-2026-10667 HIGH 7.8 Zephyr — Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains …● PoC 2026-07-12 CVE-2026-10668 LOW 2.4 Zephyr — The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data… 2026-07-12 CVE-2026-10660 MEDIUM 6.4 Zephyr — The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassemb… 2026-07-11 CVE-2026-10659 MEDIUM 4.7 Zephyr — The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks… 2026-07-07 CVE-2026-10656 MEDIUM 4.6 Zephyr — The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenc… 2026-07-05 CVE-2026-10657 LOW 3.7 Zephyr — Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve… 2026-07-05 CVE-2026-10652 MEDIUM 4.8 Zephyr — Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), …● PoC 2026-06-30 CVE-2026-10653 MEDIUM 6.4 Zephyr — The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf-… 2026-06-30 CVE-2026-10654 LOW 3.1 Zephyr — A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mi… 2026-06-30 CVE-2026-10655 MEDIUM 6.5 Zephyr — The asynchronous SNTP client in Zephyr (subsys/net/lib/sntp/sntp.c, sntp_close_async) closed the UDP socket fi… 2026-06-30 CVE-2026-9263 MEDIUM 6.5 Zephyr — The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to vali…● PoC 2026-06-30 CVE-2026-10647 MEDIUM 5.3 Zephyr — The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep… 2026-06-29 CVE-2026-10648 MEDIUM 6.2 Zephyr — mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the re… 2026-06-29 CVE-2026-7656 HIGH 8.1 Zephyr — The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_…● PoC 2026-06-29 CVE-2026-8023 HIGH 7.5 Zephyr — Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STAT…● PoC 2026-06-29 CVE-2026-10593 MEDIUM 6.5 Zephyr — The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state noti… 2026-06-28 CVE-2026-10644 MEDIUM 4.2 Zephyr — The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family,… 2026-06-28 CVE-2026-10646 HIGH 7.4 Zephyr — Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a… 2026-06-28 CVE-2026-10643 HIGH 8.7 Zephyr — Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validate… 2026-06-27 CVE-2026-13351 HIGH 7.5 Zephyr — Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a… 2026-06-25 CVE-2026-10642 MEDIUM 4.6 Zephyr — The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx… 2026-06-24 CVE-2026-10645 MEDIUM 4.9 Zephyr — The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and d… 2026-06-22 CVE-2026-10651 HIGH 7.1 Zephyr — bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held… 2026-06-22 CVE-2026-10658 HIGH 7.1 Zephyr — bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag i… 2026-06-22 CVE-2026-10641 HIGH 7.1 Zephyr — Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_…● PoC 2026-06-17 CVE-2026-10635 MEDIUM 6.3 Zephyr — On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c… 2026-06-16 CVE-2026-10636 LOW 3.7 Zephyr — In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out … 2026-06-16 CVE-2026-10637 MEDIUM 5.9 Zephyr — subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) … 2026-06-16 CVE-2026-10638 MEDIUM 5.9 Zephyr — subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try… 2026-06-16 CVE-2026-10639 MEDIUM 4.8 Zephyr — In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply pac… 2026-06-16 CVE-2026-10640 MEDIUM 4.2 Zephyr — Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/ne… 2026-06-16 CVE-2026-10634 MEDIUM 4.8 Zephyr — Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using… 2026-06-15 CVE-2026-5067 CRITICAL 9.8 Zephyr — A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade pat…● PoC 2026-06-09 CVE-2026-5068 HIGH 7.6 Zephyr — A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP… 2026-06-09