以下是对该漏洞描述信息的中文翻译: 在 LwM2M JSON 内容格式化工具中, 文件中的 函数会将解析后的 JSON 字符串复制到调用者提供的缓冲区,并在末尾添加 NUL 终止符。原有的长度检查条件为 ,该条件允许字符串长度恰好等于 的情况通过检查。在执行 填满整个缓冲区后,随后的 操作会在缓冲区末端之外写入一个字节(CWE-787:越界写入)。 字符串值及其长度直接来自接收到的 CoAP 载荷,发生在 LwM2M WRITE 操作期间。 解析从 获取的载荷;当资源类型为 时, (位于 中的 )会调用 。目标缓冲
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 3.2.0< 4.4.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 3.2.0 ~ 4.4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14696 | 6.5 MEDIUM | Ethernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustion |
| CVE-2026-14697 | 6.5 MEDIUM | IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of service |
| CVE-2026-14366 | 6.4 MEDIUM | SiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pkt |
| CVE-2026-14367 | 3.1 LOW | I3C IBI work-node free-list data race between ISR and workqueue thread |
No comments yet