中的 函数在处理携带 Block1 选项的传入 CoAP WRITE/CREATE 请求时存在漏洞。在处理传输的第一个块时,该函数先调用 ,随后在检查其返回码之前,立即将客户端选择的块大小存储到 中。然而,当静态池 中没有可用条目(因空间不足或超时)时, 会将调用方的指针设置为 NULL 并返回 。因此,后续的存储操作会解引用一个 NULL 指针。 该池中最多容纳 个条目(默认为 3),且只有当传输完成、失败或过期(超过 30 秒)后,条目才会被回收。因此,能够到达客户端 LwM2M 套接字对等方的攻击者,可以在三
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 3.7.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16513 | 7.8 HIGH | Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allo |
| CVE-2026-18413 | 7.8 HIGH | Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer si |
| CVE-2026-18414 | 7.8 HIGH | Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size |
| CVE-2026-18747 | 6.8 MEDIUM | Integer underflow of net_buf length in the MCUmgr serial (SMP over console) transport lead |
| CVE-2026-18417 | 6.5 MEDIUM | Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket reports an asyn |
| CVE-2026-18415 | 6.3 MEDIUM | Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames |
| CVE-2026-18416 | 3.7 LOW | Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_path_uri) |
No comments yet