Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zephyr — Vulnerabilities & Security Advisories 218

All 218 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in Zephyr, an open-source real-time operating system for resource-constrained embedded systems, categorized under common weakness types such as buffer overflows and improper input validation. The collection includes security advisories, flaw reports, and associated technical details ranging from initial public disclosures through to recent updates in the current development cycle, ensuring coverage of both legacy issues and newly identified risks within the Zephyr codebase and its associated components. By reviewing this aggregation, you can track vendor advisories for Zephyr to stay informed about critical patches and mitigation strategies, gain a deeper understanding of specific weakness classes that frequently affect embedded RTOS environments, and investigate a product’s vulnerability history to assess long-term security trends and patch responsiveness. This resource is designed to assist security researchers, developers, and system integrators in evaluating the security posture of Zephyr-based deployments, identifying potential attack surfaces, and aligning internal security protocols with upstream fixes. It serves as a centralized reference for correlating reported flaws with their underlying causes and recommended remediations, facilitating more robust risk management decisions for projects relying on this operating system.

Vendor: zephyrproject-rtos

CVE ID Title CVSS Severity Published
CVE-2021-3330 RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyr CWE-787 7.1 High 2021-10-12
CVE-2021-3323 Integer Underflow in 6LoWPAN IPHC Header Uncompression in Zephyr CWE-191 8.3 High 2021-10-12
CVE-2021-3322 Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr CWE-476 6.5 Medium 2021-10-12
CVE-2021-3321 Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal CWE-680 7.5 High 2021-10-12
CVE-2021-3625 Buffer overflow in Zephyr USB DFU DNLOAD CWE-122 9.6 Critical 2021-10-05
CVE-2021-3581 Buffer Access with Incorrect Length Value in zephyr CWE-805 7.0 High 2021-10-05
CVE-2021-3510 Zephyr JSON decoder incorrectly decodes array of array CWE-588 7.5 High 2021-10-05
CVE-2021-3436 BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known CWE-694 4.3 Medium 2021-10-05
CVE-2021-3319 DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses CWE-476 6.5 Medium 2021-10-05
CVE-2021-3320 Type Confusion in 802154 ACK Frames Handling CWE-476 5.9 Medium 2021-05-24
CVE-2020-13603 Integer Overflow in memory allocating functions CWE-190 6.9 Medium 2021-05-24
CVE-2020-13601 Possible read out of bounds in dns read CWE-125 9.0 Critical 2021-05-24
CVE-2020-13602 Remote Denial of Service in LwM2M do_write_op_tlv CWE-20 4.0 Medium 2021-05-24
CVE-2020-13600 Malformed SPI in response for eswifi can corrupt kernel memory CWE-122 7.0 High 2021-05-24
CVE-2020-13598 FS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_stat CWE-121 6.3 Medium 2021-05-24
CVE-2020-13599 Security problem with settings and littlefs CWE-276 3.3 Low 2021-05-24
CVE-2020-10072 Improper Handling of Insufficient Permissions or Privileges in zephyr CWE-280 5.9 Medium 2021-05-24
CVE-2020-10066 Incorrect Error Handling in Bluetooth HCI core CWE-476 2.5 Low 2021-05-24
CVE-2020-10069 Zephyr Bluetooth unchecked packet data results in denial of service CWE-233 4.3 Medium 2021-05-24
CVE-2020-10065 Missing Size Checks in Bluetooth HCI over SPI CWE-130 3.8 Low 2021-05-24
CVE-2020-10064 Improper Input Frame Validation in ieee802154 Processing CWE-121 8.3 High 2021-05-24
CVE-2020-10071 Insufficient publish message length validation in MQTT CWE-120 9.0 Critical 2020-06-05
CVE-2020-10061 Error handling invalid packet sequence CWE-119 8.1 High 2020-06-05
CVE-2020-10062 Packet length decoding error in MQTT CWE-193 9.0 Critical 2020-06-05
CVE-2020-10063 Remote Denial of Service in CoAP Option Parsing Due To Integer Overflow CWE-190 6.8 Medium 2020-06-05
CVE-2020-10068 Zephyr Bluetooth DLE duplicate requests vulnerability CWE-20 5.1 Medium 2020-06-05
CVE-2020-10070 MQTT buffer overflow on receive buffer CWE-120 9.0 Critical 2020-06-05
CVE-2020-10060 UpdateHub Might Dereference An Uninitialized Pointer CWE-119 8.0 High 2020-05-11
CVE-2020-10067 Integer Overflow In is_in_region Allows User Thread To Access Kernel Memory CWE-190 7.5 High 2020-05-11
CVE-2020-10058 Multiple Syscalls In kscan Subsystem Performs No Argument Validation CWE-20 7.8 High 2020-05-11

All 218 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.