Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Zephyr — Vulnerabilities & Security Advisories 211

All 211 CVE vulnerabilities found in Zephyr, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in Zephyr, an open-source real-time operating system for resource-constrained embedded systems, categorized under common weakness types such as buffer overflows and improper input validation. The collection includes security advisories, flaw reports, and associated technical details ranging from initial public disclosures through to recent updates in the current development cycle, ensuring coverage of both legacy issues and newly identified risks within the Zephyr codebase and its associated components. By reviewing this aggregation, you can track vendor advisories for Zephyr to stay informed about critical patches and mitigation strategies, gain a deeper understanding of specific weakness classes that frequently affect embedded RTOS environments, and investigate a product’s vulnerability history to assess long-term security trends and patch responsiveness. This resource is designed to assist security researchers, developers, and system integrators in evaluating the security posture of Zephyr-based deployments, identifying potential attack surfaces, and aligning internal security protocols with upstream fixes. It serves as a centralized reference for correlating reported flaws with their underlying causes and recommended remediations, facilitating more robust risk management decisions for projects relying on this operating system.

Vendor: zephyrproject-rtos

CVE IDTitleCVSSSeverityPublished
CVE-2026-10654 RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic CWE-362 3.1 Low2026-06-30
CVE-2026-10653 Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref CWE-415 6.4 Medium2026-06-30
CVE-2026-9263 Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets CWE-125 6.5 Medium2026-06-30
CVE-2026-10652 Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`) CWE-125 4.8 Medium2026-06-30
CVE-2026-10648 NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion CWE-476 6.2 Medium2026-06-29
CVE-2026-8023 Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read CWE-22 7.5 High2026-06-29
CVE-2026-7656 Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack CWE-290 8.1 High2026-06-29
CVE-2026-10647 Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure CWE-833 5.3 Medium2026-06-29
CVE-2026-10593 Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling CWE-476 6.5 Medium2026-06-28
CVE-2026-10646 Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation CWE-416 7.4 High2026-06-28
CVE-2026-10644 Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer CWE-787 4.2 Medium2026-06-28
CVE-2026-10643 Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check) CWE-787 8.7 High2026-06-27
CVE-2026-13351 net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets CWE-772 7.5 High2026-06-25
CVE-2026-10642 Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control CWE-835 4.6 Medium2026-06-24
CVE-2026-10658 Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validation CWE-787 7.1 High2026-06-22
CVE-2026-10651 Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`) CWE-20 7.1 High2026-06-22
CVE-2026-10645 Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image CWE-125 4.9 Medium2026-06-22
CVE-2026-10641 Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values) CWE-787 7.1 High2026-06-17
CVE-2026-10640 Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`) CWE-416 4.2 Medium2026-06-16
CVE-2026-10639 Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()` CWE-416 4.8 Medium2026-06-16
CVE-2026-10638 Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error CWE-416 5.9 Medium2026-06-16
CVE-2026-10637 Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query CWE-416 5.9 Medium2026-06-16
CVE-2026-10636 Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`) CWE-416 3.7 Low2026-06-16
CVE-2026-10635 Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-init CWE-416 6.3 Medium2026-06-16
CVE-2026-10634 Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callback CWE-416 4.8 Medium2026-06-15
CVE-2026-5068 bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data CWE-787 7.6 High2026-06-09
CVE-2026-5067 Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Key CWE-170 9.8 Critical2026-06-09
CVE-2026-5066 net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect function CWE-787 6.3 Medium2026-06-04
CVE-2026-5589 Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem. CWE-787--2026-06-04
CVE-2026-5071 can: Local Denial of Service via SocketCAN Send CWE-125 6.1 Medium2026-05-30

All 211 known CVE vulnerabilities affecting Zephyr with full Chinese analysis, references, and POCs where available.