Zephyr 系统中的 virtio 驱动程序未对 virtio 设备写入使用环(used ring)的描述符链头 ID 进行验证。在 函数(位于 )中,设备写入的 被直接用作 和 数组的索引,而这两个数组均仅分配了恰好 个条目。 中存储的是包含回调函数指针和不透明参数(opaque)的 回调条目,随后通过索引获取回调指针并以 的形式进行调用。 由于该 ID 被作为 16 位无符号整数直接消费且未进行边界检查,恶意或已遭控制的 virtio 后端(例如不受信任的 hypervisor,或通过 PCI 或 MMIO
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 4.2.0 ~ 4.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9728 | 6.4 MEDIUM | TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory |
| CVE-2026-13343 | 5.3 MEDIUM | Uninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responder |
| CVE-2026-13213 | 5.3 MEDIUM | Bluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects before bt_has_re |
No comments yet