zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 Zephyr Project Zephyr 1.14.0版本至4.5.0之前版本存在资源管理错误漏洞,该漏洞源于动态内核对象跟踪中的释放后重用问题,在SMP系统中,由于列表遍历和节点释放使用不同的自旋锁,可能导致内核内存损坏,造成权限提升或内核崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 1.14.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 1.14.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10666 | 8.1 HIGH | Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/ne |
| CVE-2026-10665 | 7.4 HIGH | Heap buffer overflow on WireGuard receive path via unbounded incoming packet length |
| CVE-2026-10663 | 6.1 MEDIUM | Use-after-free / double-free of the root USB device in the experimental USB host stack |
| CVE-2026-10664 | 5.0 MEDIUM | Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow cou |
| CVE-2026-10668 | 2.4 LOW | Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver |
No comments yet