Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zephyr — Vulnerabilities & Security Advisories 222

All 222 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in Zephyr, an open-source real-time operating system for resource-constrained embedded systems, categorized under common weakness types such as buffer overflows and improper input validation. The collection includes security advisories, flaw reports, and associated technical details ranging from initial public disclosures through to recent updates in the current development cycle, ensuring coverage of both legacy issues and newly identified risks within the Zephyr codebase and its associated components. By reviewing this aggregation, you can track vendor advisories for Zephyr to stay informed about critical patches and mitigation strategies, gain a deeper understanding of specific weakness classes that frequently affect embedded RTOS environments, and investigate a product’s vulnerability history to assess long-term security trends and patch responsiveness. This resource is designed to assist security researchers, developers, and system integrators in evaluating the security posture of Zephyr-based deployments, identifying potential attack surfaces, and aligning internal security protocols with upstream fixes. It serves as a centralized reference for correlating reported flaws with their underlying causes and recommended remediations, facilitating more robust risk management decisions for projects relying on this operating system.

Vendor: zephyrproject-rtos

CVE ID Title CVSS Severity Published
CVE-2026-10639 Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()` CWE-416 4.8 Medium 2026-06-16
CVE-2026-10638 Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error CWE-416 5.9 Medium 2026-06-16
CVE-2026-10637 Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query CWE-416 5.9 Medium 2026-06-16
CVE-2026-10636 Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`) CWE-416 3.7 Low 2026-06-16
CVE-2026-10635 Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-init CWE-416 6.3 Medium 2026-06-16
CVE-2026-10634 Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callback CWE-416 4.8 Medium 2026-06-15
CVE-2026-5068 bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data CWE-787 7.6 High 2026-06-09
CVE-2026-5067 Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Key CWE-170 9.8 Critical 2026-06-09
CVE-2026-5066 net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect function CWE-787 6.3 Medium 2026-06-04
CVE-2026-5589 Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem. CWE-787 - - 2026-06-04
CVE-2026-5071 can: Local Denial of Service via SocketCAN Send CWE-125 6.1 Medium 2026-05-30
CVE-2026-5072 ptp: Potential Denial of Service via PTP Interval Shift - - 2026-05-22
CVE-2026-1681 net: Stack Overflow with Ping (to own IP Address) via Shell CWE-674 6.1 Medium 2026-05-12
CVE-2026-1677 net: TLS 1.2 connections allowed on TLS 1.3 sockets CWE-757 5.3 Medium 2026-05-11
CVE-2026-5590 net: ip/tcp: Null pointer dereference can be triggered by a race condition CWE-476 6.4 Medium 2026-04-05
CVE-2026-1679 net: eswifi socket send payload length not bounded CWE-120 7.3 High 2026-03-27
CVE-2026-4179 stm32: usb: Infinite while loop in Interrupt Handler CWE-835 6.1 Medium 2026-03-14
CVE-2026-0849 crypto: ATAES132A response length allows stack buffer overflow CWE-120 3.8 Low 2026-03-14
CVE-2026-1678 dns: memory‑safety issue in the DNS name parser CWE-787 9.4 Critical 2026-03-05
CVE-2025-12899 net: icmp: Out of bound memory read CWE-843 6.5 Medium 2026-01-30
CVE-2025-12035 Bluetooth: Integer Overflow in Bluetooth Classic (BR/EDR) L2CAP CWE-190 6.5 Medium 2025-12-15
CVE-2025-9557 Bluetooth: Mesh: Out-of-Bound Write in gen_prov_cont CWE-120 7.6 High 2025-11-26
CVE-2025-9558 Bluetooth: Mesh: Out-of-Bound Write in gen_prov_start CWE-120 7.6 High 2025-11-26
CVE-2025-9408 Userspace privilege escalation vulnerability on Cortex M CWE-270 8.2 High 2025-11-11
CVE-2025-12890 Bluetooth: peripheral: Invalid handling of malformed connection request CWE-703 6.5 Medium 2025-11-07
CVE-2025-10456 Bluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requests CWE-190 7.1 High 2025-09-19
CVE-2025-10458 Bluetooth: le_conn_rsp does not sanitize CID, MTU, MPS values CWE-130 7.6 High 2025-09-19
CVE-2025-7403 Bluetooth: bt_conn_tx_processor unsafe handling CWE-123 7.6 High 2025-09-19
CVE-2025-10457 Bluetooth: Out-Of-Context le_conn_rsp Handling CWE-358 4.3 Medium 2025-09-19
CVE-2025-2962 Infinite loop in dns_copy_qname CWE-835 8.2 High 2025-06-24

All 222 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.