zephyrproject zephyr是zephyrproject组织开源的一个面向物联网设备的实时操作系统。 zephyrproject zephyr 4.4.0版本至4.4.2之前版本存在资源管理错误漏洞,该漏洞源于蓝牙HCI驱动中缓冲区所有权处理错误,错误路径上调用net_buf_unref导致双重释放和释放后重用,可能造成拒绝服务或内存损坏。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 4.4.0< 4.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 4.4.0 ~ 4.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11894 | 5.9 MEDIUM | Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error paths |
| CVE-2026-12052 | 5.2 MEDIUM | Out-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the r |
| CVE-2026-12051 | 4.6 MEDIUM | NULL pointer dereference in USB DFU device_next download handler (handle_download) |
| CVE-2026-11985 | 3.6 LOW | Cross-thread FPU register leak on ARM when FPU enabled without register sharing |
No comments yet