zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 2.0.0版本至4.4.1版本存在竞争条件问题漏洞,该漏洞源于对ctx访问未进行序列化,prepare_fds()函数写入ctx.fds时缺少边界检查,存在竞争条件,可能导致更新子系统内部状态损坏和固件更新路径拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 2.0.0< 4.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 2.0.0 ~ 4.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-8718 | 8.4 HIGH | Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Z |
| CVE-2026-11810 | 7.5 HIGH | NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS) |
| CVE-2026-11809 | 3.7 LOW | UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata |
| CVE-2026-11811 | 3.7 LOW | Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resourc |
No comments yet