zephyrproject zephyr是zephyrproject组织开源的一款实时操作系统内核。 Zephyr 3.3.0版本至4.5.0之前版本存在缓冲区错误漏洞,该漏洞源于蓝牙控制器ISO适配层未能验证帧ISO PDU起始段长度字段,可能导致远程攻击者触发越界读取,造成信息泄露和潜在拒绝服务攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| zephyrproject | zephyr | 3.3.0< 4.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| zephyrproject | zephyr | 3.3.0 ~ 4.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10655 | 6.5 MEDIUM | Use-after-free race in SNTP async client when closing the socket while the socket service |
| CVE-2026-10653 | 6.4 MEDIUM | Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concu |
| CVE-2026-10652 | 4.8 MEDIUM | Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`) |
| CVE-2026-10654 | 3.1 LOW | RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Ze |
No comments yet