Zephyr是Zephyr组织开源的一个可扩展的实时操作系统 (RTOS)。 Zephyr 1.6.0版本至4.5.0之前版本存在竞争条件问题漏洞,该漏洞源于Zephyr Bluetooth Classic RFCOMM主机堆栈中存在竞争条件问题,当本地设备和相连对端同时发起双向会话断开时,可能导致会话永久挂起,底层L2CAP通道无法释放,会话池耗尽,从而拒绝RFCOMM服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 1.6.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 1.6.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9263 | 6.5 MEDIUM | Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memor |
| CVE-2026-10655 | 6.5 MEDIUM | Use-after-free race in SNTP async client when closing the socket while the socket service |
| CVE-2026-10653 | 6.4 MEDIUM | Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concu |
| CVE-2026-10652 | 4.8 MEDIUM | Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`) |
No comments yet