Zephyrproject
49 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-10674
MEDIUM 5.5
Zephyr — The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is en…
2026-07-21
CVE-2026-10675
MEDIUM 4.3
Zephyr — In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() resche…
2026-07-21
CVE-2026-10677
MEDIUM 6.5
Zephyr — The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the use…
2026-07-21
CVE-2026-10678
HIGH 8.1
Zephyr — The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-reg…
2026-07-21
CVE-2026-10679
LOW 3.3
Zephyr — The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency…
2026-07-21
CVE-2026-10680
HIGH 7.6
Zephyr — The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/…
2026-07-21
CVE-2026-10673
HIGH 8.3
Zephyr — The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles rece…● PoC
2026-07-15
CVE-2026-10669
HIGH 7.8
Zephyr — On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/m…
2026-07-14
CVE-2026-10670
MEDIUM 5.5
Zephyr — The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy(…
2026-07-14
CVE-2026-10671
HIGH 7.1
Zephyr — In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c u…
2026-07-14
CVE-2026-10672
HIGH 8.2
Zephyr — subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (c…● PoC
2026-07-14
CVE-2026-10663
MEDIUM 6.1
Zephyr — In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usb…
2026-07-12
CVE-2026-10664
MEDIUM 5
Zephyr — The nRF70 Wi-Fi driver's power-save event handler nrf_wifi_event_proc_get_power_save_info() in drivers/wifi/nr…● PoC
2026-07-12
CVE-2026-10665
HIGH 7.4
Zephyr — In Zephyr's WireGuard subsystem (subsys/net/lib/wireguard), wg_process_data_message() in wg_crypto.c linearize…● PoC
2026-07-12
CVE-2026-10666
HIGH 8.1
Zephyr — parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") …● PoC
2026-07-12
CVE-2026-10667
HIGH 7.8
Zephyr — Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains …● PoC
2026-07-12
CVE-2026-10668
LOW 2.4
Zephyr — The Nuvoton NuMaker HSUSBD USB device-controller driver (drivers/usb/udc/udc_numaker.c) armed the control Data…
2026-07-12
CVE-2026-10660
MEDIUM 6.4
Zephyr — The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassemb…
2026-07-11
CVE-2026-10659
MEDIUM 4.7
Zephyr — The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks…
2026-07-07
CVE-2026-10656
MEDIUM 4.6
Zephyr — The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenc…
2026-07-05
CVE-2026-10657
LOW 3.7
Zephyr — Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve…
2026-07-05
CVE-2026-10652
MEDIUM 4.8
Zephyr — Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), …● PoC
2026-06-30
CVE-2026-10653
MEDIUM 6.4
Zephyr — The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf-…
2026-06-30
CVE-2026-10654
LOW 3.1
Zephyr — A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mi…
2026-06-30
CVE-2026-10655
MEDIUM 6.5
Zephyr — The asynchronous SNTP client in Zephyr (subsys/net/lib/sntp/sntp.c, sntp_close_async) closed the UDP socket fi…
2026-06-30
CVE-2026-9263
MEDIUM 6.5
Zephyr — The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to vali…● PoC
2026-06-30
CVE-2026-10647
MEDIUM 5.3
Zephyr — The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep…
2026-06-29
CVE-2026-10648
MEDIUM 6.2
Zephyr — mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the re…
2026-06-29
CVE-2026-7656
HIGH 8.1
Zephyr — The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_…● PoC
2026-06-29
CVE-2026-8023
HIGH 7.5
Zephyr — Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STAT…● PoC
2026-06-29
CVE-2026-10593
MEDIUM 6.5
Zephyr — The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state noti…
2026-06-28
CVE-2026-10644
MEDIUM 4.2
Zephyr — The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family,…
2026-06-28
CVE-2026-10646
HIGH 7.4
Zephyr — Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a…
2026-06-28
CVE-2026-10643
HIGH 8.7
Zephyr — Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validate…
2026-06-27
CVE-2026-13351
HIGH 7.5
Zephyr — Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a…
2026-06-25
CVE-2026-10642
MEDIUM 4.6
Zephyr — The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx…
2026-06-24
CVE-2026-10645
MEDIUM 4.9
Zephyr — The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and d…
2026-06-22
CVE-2026-10651
HIGH 7.1
Zephyr — bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held…
2026-06-22
CVE-2026-10658
HIGH 7.1
Zephyr — bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag i…
2026-06-22
CVE-2026-10641
HIGH 7.1
Zephyr — Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_…● PoC
2026-06-17
CVE-2026-10635
MEDIUM 6.3
Zephyr — On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c…
2026-06-16
CVE-2026-10636
LOW 3.7
Zephyr — In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out …
2026-06-16
CVE-2026-10637
MEDIUM 5.9
Zephyr — subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) …
2026-06-16
CVE-2026-10638
MEDIUM 5.9
Zephyr — subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try…
2026-06-16
CVE-2026-10639
MEDIUM 4.8
Zephyr — In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icmpv4.c builds an echo-reply pac…
2026-06-16
CVE-2026-10640
MEDIUM 4.2
Zephyr — Zephyr's IPv6 Neighbor Discovery send paths (net_ipv6_send_na, net_ipv6_send_ns, net_ipv6_send_rs in subsys/ne…
2026-06-16
CVE-2026-10634
MEDIUM 4.8
Zephyr — Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using…
2026-06-15
CVE-2026-5067
CRITICAL 9.8
Zephyr — A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade pat…● PoC
2026-06-09
CVE-2026-5068
HIGH 7.6
Zephyr — A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP…
2026-06-09