zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.0.0版本至4.4.2之前版本存在资源管理错误漏洞,该漏洞源于subsys/mgmt/updatehub/updatehub.c文件中的start_coap_client()函数在连接建立失败路径上泄漏CoAP/DTLS套接字描述符,由于错误处理中ret标志设置不当导致清理函数未被调用,攻击者可通过网络干扰连接触发,造成套接字/net_contex
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 2.0.0< 4.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 2.0.0 ~ 4.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-8718 | 8.4 HIGH | Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Z |
| CVE-2026-11810 | 7.5 HIGH | NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS) |
| CVE-2026-11809 | 3.7 LOW | UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata |
| CVE-2026-11812 | 2.5 LOW | UpdateHub: race condition on shared context causes out-of-bounds write and DoS |
No comments yet