zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 3.7.0版本至4.4.2之前版本存在异常处理不当漏洞,该漏洞源于UpdateHub固件更新代理的probe handler解析JSON元数据时未检查内部对象数组是否为空,可能导致空指针解引用,远程触发拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 3.7.0< 4.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 3.7.0 ~ 4.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-8718 | 8.4 HIGH | Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Z |
| CVE-2026-11809 | 3.7 LOW | UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata |
| CVE-2026-11811 | 3.7 LOW | Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resourc |
| CVE-2026-11812 | 2.5 LOW | UpdateHub: race condition on shared context causes out-of-bounds write and DoS |
No comments yet