zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 Zephyr Project Zephyr 3.3.0及之前版本至4.4.0版本存在资源管理错误漏洞,该漏洞源于IPv6邻居发现发送路径中,在数据包已成功发送后仍调用net_pkt_iface(pkt)读取已释放的slab块中的iface指针,当启用CONFIG_NET_STATISTICS_PER_INTERFACE时该指针被解引用以递增统计计数器,导致释放后重用。任何未经验证的链路上节点通过发送ICM
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 3.3.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 3.3.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10635 | 6.3 MEDIUM | Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-do |
| CVE-2026-10638 | 5.9 MEDIUM | Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo rep |
| CVE-2026-10637 | 5.9 MEDIUM | Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query |
| CVE-2026-10639 | 4.8 MEDIUM | Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_han |
| CVE-2026-10636 | 3.7 LOW | Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`) |
No comments yet