以下是该漏洞描述信息的中文翻译: 在 中的 UMP Stream 响应库,使用一个 16 字节的 (由 组成)来构建回复数据包。函数 和 仅填充前两个字(即 和 ),而在修复之前,它们将结果声明为未初始化的局部变量( )。因此,剩余的两个字( 和 )会保留栈上残留的旧数据。 Endpoint Info 和 Function Block Info 通知属于 UMP Stream 消息( ),长度为 4 个字(16 字节)。因此,整个 16 字节的数据包——包括两个未初始化的字——会通过 原封不动地发送出去。该响应器由
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 4.3.0< 4.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 4.3.0 ~ 4.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13212 | 8.8 HIGH | Zephyr virtio driver calls an arbitrary function pointer from an out-of-range used-ring de |
| CVE-2026-9728 | 6.4 MEDIUM | TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory |
| CVE-2026-13213 | 5.3 MEDIUM | Bluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects before bt_has_re |
No comments yet