Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Zephyr — Vulnerabilities & Security Advisories 217

All 217 CVE vulnerabilities found in Zephyr, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in Zephyr, an open-source real-time operating system for resource-constrained embedded systems, categorized under common weakness types such as buffer overflows and improper input validation. The collection includes security advisories, flaw reports, and associated technical details ranging from initial public disclosures through to recent updates in the current development cycle, ensuring coverage of both legacy issues and newly identified risks within the Zephyr codebase and its associated components. By reviewing this aggregation, you can track vendor advisories for Zephyr to stay informed about critical patches and mitigation strategies, gain a deeper understanding of specific weakness classes that frequently affect embedded RTOS environments, and investigate a product’s vulnerability history to assess long-term security trends and patch responsiveness. This resource is designed to assist security researchers, developers, and system integrators in evaluating the security posture of Zephyr-based deployments, identifying potential attack surfaces, and aligning internal security protocols with upstream fixes. It serves as a centralized reference for correlating reported flaws with their underlying causes and recommended remediations, facilitating more robust risk management decisions for projects relying on this operating system.

Vendor: zephyrproject-rtos

CVE IDTitleCVSSSeverityPublished
CVE-2026-12634 Out-of-bounds stack write in the settings NVS backend from over-reported nvs_read length CWE-787 5.3 Medium2026-08-19
CVE-2026-12522 Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fields CWE-787 8.8 High2026-08-19
CVE-2026-12633 Out-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router Advertisement CWE-787 8.1 High2026-08-19
CVE-2026-12632 Out-of-bounds read in Zephyr PTP message parsing from unvalidated message type CWE-125 6.5 Medium2026-08-18
CVE-2026-12631 Broken access-control denial in k_thread_join/k_thread_abort syscall validation in Zephyr kernel CWE-862 6.5 Medium2026-08-18
CVE-2026-12520 Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlers CWE-787 6.4 Medium2026-08-18
CVE-2026-12519 Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsing CWE-787 5.0 Medium2026-08-17
CVE-2026-9771 Missing device-pointer validation in flash_copy() syscall allows userspace privilege escalation CWE-822 8.8 High2026-08-17
CVE-2026-12630 6LoWPAN IPHC uncompression out-of-bounds read on reserved destination addressing mode CWE-125 4.3 Medium2026-08-17
CVE-2026-12629 PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of service CWE-835 4.6 Medium2026-08-17
CVE-2026-12366 Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal CWE-416 8.8 High2026-08-14
CVE-2026-12365 Use-after-free in Zephyr delayable work-queue cancellation under SMP timing race CWE-416 5.8 Medium2026-08-14
CVE-2026-12364 Missing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and denial of service CWE-822 8.4 High2026-08-14
CVE-2026-12363 Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0 CWE-787 4.2 Medium2026-08-14
CVE-2026-12236 Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length CWE-835 6.5 Medium2026-08-13
CVE-2026-12235 Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787) CWE-787 6.3 Medium2026-08-12
CVE-2026-12234 TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write CWE-367 7.8 High2026-08-12
CVE-2026-12233 Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention CWE-665 5.9 Medium2026-08-12
CVE-2026-12232 Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties CWE-125 6.1 Medium2026-08-12
CVE-2026-12052 Out-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the response CWE-787 5.2 Medium2026-08-11
CVE-2026-12051 NULL pointer dereference in USB DFU device_next download handler (handle_download) CWE-476 4.6 Medium2026-08-11
CVE-2026-11894 Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error paths CWE-415 5.9 Medium2026-08-11
CVE-2026-11985 Cross-thread FPU register leak on ARM when FPU enabled without register sharing CWE-200 3.6 Low2026-08-11
CVE-2026-11893 Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb) CWE-415 5.9 Medium2026-08-11
CVE-2026-11812 UpdateHub: race condition on shared context causes out-of-bounds write and DoS CWE-362 2.5 Low2026-08-10
CVE-2026-11811 Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS CWE-772 3.7 Low2026-08-10
CVE-2026-8718 Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLS CWE-787 8.4 High2026-08-10
CVE-2026-11809 UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata CWE-125 3.7 Low2026-08-10
CVE-2026-11810 NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS) CWE-476 7.5 High2026-08-10
CVE-2026-11742 Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock CWE-416 3.6 Low2026-08-07

All 217 known CVE vulnerabilities affecting Zephyr with full Chinese analysis, references, and POCs where available.