zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyrproject zephyr存在缓冲区错误漏洞,该漏洞源于lwm2m_pull_context.c将固件更新包URI复制到固定静态缓冲区时未进行长度验证,可能导致相邻静态内存的越界读取,进而造成信息泄露和拒绝服务。以下版本受到影响:3.0.0至4.4.0版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 3.0.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 3.0.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10669 | 7.8 HIGH | Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall poi |
| CVE-2026-10671 | 7.1 HIGH | User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_U |
| CVE-2026-10670 | 5.5 MEDIUM | User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall v |
No comments yet