zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyrproject zephyr 2.0.0版本至4.5.0之前版本存在异常处理不当漏洞,该漏洞源于k_thread_name_copy()系统调用的验证处理程序在解引用k_object_find()返回的struct k_object之前未检查其是否为NULL,导致未授权用户模式线程通过未注册的指针触发空指针解引用,从而造成内核模式故障、系统挂起或重启,导致拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 3.7.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 3.7.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10672 | 8.2 HIGH | Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI) |
| CVE-2026-10669 | 7.8 HIGH | Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall poi |
| CVE-2026-10671 | 7.1 HIGH | User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_U |
No comments yet