zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 zephyrproject Zephyr 1.12.0版本至4.4.1版本存在资源管理错误漏洞,该漏洞源于内核中的CONFIG_USERSPACE系统调用验证器z_vrfy_k_poll()在验证用户提供的k_poll_event[]时分配内核侧副本后未能释放内存,可能导致用户线程通过伪造对象句柄并重复泄漏分配来耗尽共享内核堆,从而造成系统级拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 1.12.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 1.12.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10678 | 8.1 HIGH | NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an una |
| CVE-2026-10680 | 7.6 HIGH | Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` |
| CVE-2026-10674 | 5.5 MEDIUM | DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disab |
| CVE-2026-10675 | 4.3 MEDIUM | Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re |
| CVE-2026-10679 | 3.3 LOW | Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS) |
No comments yet