zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 Zephyr Project Zephyr 4.4.0版本及4.5.0之前版本存在资源管理错误漏洞,该漏洞源于USB主机堆栈中usbh_device_disconnect()函数未清除缓存指针ctx->root,导致释放后重用和双重释放,攻击者可通过物理USB访问触发拒绝服务和内存破坏。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 4.4.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 4.4.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10666 | 8.1 HIGH | Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/ne |
| CVE-2026-10667 | 7.8 HIGH | SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable |
| CVE-2026-10665 | 7.4 HIGH | Heap buffer overflow on WireGuard receive path via unbounded incoming packet length |
| CVE-2026-10664 | 5.0 MEDIUM | Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow cou |
| CVE-2026-10668 | 2.4 LOW | Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver |
No comments yet