zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 Zephyr Project Zephyr 4.4.0版本存在缓冲区错误漏洞,该漏洞源于WireGuard子系统中wg_crypto.c文件的wg_process_data_message()函数对inbound transport-data payload进行线性化处理时,未正确限制目标缓冲区容量和复制长度,导致data_len超过CONFIG_WIREGUARD_BUF_LEN时发生越界写入,造成内存
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 4.4.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 4.4.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10666 | 8.1 HIGH | Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/ne |
| CVE-2026-10667 | 7.8 HIGH | SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable |
| CVE-2026-10663 | 6.1 MEDIUM | Use-after-free / double-free of the root USB device in the experimental USB host stack |
| CVE-2026-10664 | 5.0 MEDIUM | Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow cou |
| CVE-2026-10668 | 2.4 LOW | Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver |
No comments yet