zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyrproject Zephyr 4.4.1及之前版本存在资源管理错误漏洞,该漏洞源于在Bluetooth Mesh PB-ADV provisioning bearer中,prov_msg_recv()函数无条件重新调度协议看门狗定时器,即使链接已失效,导致远程未经验证攻击者通过BLE广播信道可发起持续性拒绝服务攻击,使设备保持在无法配置状态。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 3.5.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 3.5.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10678 | 8.1 HIGH | NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an una |
| CVE-2026-10680 | 7.6 HIGH | Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` |
| CVE-2026-10677 | 6.5 MEDIUM | Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the |
| CVE-2026-10674 | 5.5 MEDIUM | DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disab |
| CVE-2026-10679 | 3.3 LOW | Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS) |
No comments yet