Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Zephyr — Vulnerabilities & Security Advisories 217

All 217 CVE vulnerabilities found in Zephyr, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in Zephyr, an open-source real-time operating system for resource-constrained embedded systems, categorized under common weakness types such as buffer overflows and improper input validation. The collection includes security advisories, flaw reports, and associated technical details ranging from initial public disclosures through to recent updates in the current development cycle, ensuring coverage of both legacy issues and newly identified risks within the Zephyr codebase and its associated components. By reviewing this aggregation, you can track vendor advisories for Zephyr to stay informed about critical patches and mitigation strategies, gain a deeper understanding of specific weakness classes that frequently affect embedded RTOS environments, and investigate a product’s vulnerability history to assess long-term security trends and patch responsiveness. This resource is designed to assist security researchers, developers, and system integrators in evaluating the security posture of Zephyr-based deployments, identifying potential attack surfaces, and aligning internal security protocols with upstream fixes. It serves as a centralized reference for correlating reported flaws with their underlying causes and recommended remediations, facilitating more robust risk management decisions for projects relying on this operating system.

Vendor: zephyrproject-rtos

CVE IDTitleCVSSSeverityPublished
CVE-2026-11743 Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write CWE-125 6.6 Medium2026-08-07
CVE-2026-11368 Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer CWE-416 7.1 High2026-08-04
CVE-2026-10849 Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body CWE-122 8.2 High2026-08-03
CVE-2026-10848 Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg) CWE-125 7.0 High2026-08-02
CVE-2026-10774 PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS CWE-401 2.4 Low2026-08-02
CVE-2026-10773 Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name) CWE-125 5.4 Medium2026-08-01
CVE-2026-2411 Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values CWE-863 6.5 Medium2026-08-01
CVE-2026-10686 Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers CWE-835 5.8 Medium2026-07-31
CVE-2026-10685 Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler CWE-416 7.6 High2026-07-31
CVE-2026-10684 Out-of-bounds read in coredump shell when printing stored-dump target code CWE-125 3.0 Low2026-07-29
CVE-2026-10683 DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS) CWE-835 2.4 Low2026-07-27
CVE-2026-10682 Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace CWE-787 6.6 Medium2026-07-27
CVE-2026-10681 SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot CWE-362 6.5 Medium2026-07-25
CVE-2026-7007 Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image CWE-369 4.6 Medium2026-07-24
CVE-2026-10680 Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow CWE-125 7.6 High2026-07-21
CVE-2026-10679 Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS) CWE-369 3.3 Low2026-07-21
CVE-2026-10677 Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool CWE-401 6.5 Medium2026-07-21
CVE-2026-10678 NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller CWE-476 8.1 High2026-07-21
CVE-2026-10675 Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS) CWE-400 4.3 Medium2026-07-21
CVE-2026-10674 DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled CWE-617 5.5 Medium2026-07-21
CVE-2026-10673 Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly CWE-787 8.3 High2026-07-15
CVE-2026-10671 User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`) CWE-825 7.1 High2026-07-14
CVE-2026-10672 Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI) CWE-125 8.2 High2026-07-14
CVE-2026-10670 User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier CWE-476 5.5 Medium2026-07-14
CVE-2026-10669 Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation CWE-787 7.8 High2026-07-14
CVE-2026-10668 Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver CWE-400 2.4 Low2026-07-12
CVE-2026-10667 SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads CWE-416 7.8 High2026-07-12
CVE-2026-10665 Heap buffer overflow on WireGuard receive path via unbounded incoming packet length CWE-787 7.4 High2026-07-12
CVE-2026-10666 Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c` CWE-121 8.1 High2026-07-12
CVE-2026-10664 Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count) CWE-787 5.0 Medium2026-07-12

All 217 known CVE vulnerabilities affecting Zephyr with full Chinese analysis, references, and POCs where available.