Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zephyr — Vulnerabilities & Security Advisories 211

All 211 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in Zephyr, an open-source real-time operating system for resource-constrained embedded systems, categorized under common weakness types such as buffer overflows and improper input validation. The collection includes security advisories, flaw reports, and associated technical details ranging from initial public disclosures through to recent updates in the current development cycle, ensuring coverage of both legacy issues and newly identified risks within the Zephyr codebase and its associated components. By reviewing this aggregation, you can track vendor advisories for Zephyr to stay informed about critical patches and mitigation strategies, gain a deeper understanding of specific weakness classes that frequently affect embedded RTOS environments, and investigate a product’s vulnerability history to assess long-term security trends and patch responsiveness. This resource is designed to assist security researchers, developers, and system integrators in evaluating the security posture of Zephyr-based deployments, identifying potential attack surfaces, and aligning internal security protocols with upstream fixes. It serves as a centralized reference for correlating reported flaws with their underlying causes and recommended remediations, facilitating more robust risk management decisions for projects relying on this operating system.

Vendor: zephyrproject-rtos

CVE IDTitleCVSSSeverityPublished
CVE-2026-12519 Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsing CWE-787 5.0 Medium2026-08-17
CVE-2026-9771 Missing device-pointer validation in flash_copy() syscall allows userspace privilege escalation CWE-822 8.8 High2026-08-17
CVE-2026-12630 6LoWPAN IPHC uncompression out-of-bounds read on reserved destination addressing mode CWE-125 4.3 Medium2026-08-17
CVE-2026-12629 PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of service CWE-835 4.6 Medium2026-08-17
CVE-2026-12366 Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal CWE-416 8.8 High2026-08-14
CVE-2026-12365 Use-after-free in Zephyr delayable work-queue cancellation under SMP timing race CWE-416 5.8 Medium2026-08-14
CVE-2026-12364 Missing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and denial of service CWE-822 8.4 High2026-08-14
CVE-2026-12363 Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0 CWE-787 4.2 Medium2026-08-14
CVE-2026-12236 Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length CWE-835 6.5 Medium2026-08-13
CVE-2026-12235 Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787) CWE-787 6.3 Medium2026-08-12
CVE-2026-12234 TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write CWE-367 7.8 High2026-08-12
CVE-2026-12233 Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention CWE-665 5.9 Medium2026-08-12
CVE-2026-12232 Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties CWE-125 6.1 Medium2026-08-12
CVE-2026-12052 Out-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the response CWE-787 5.2 Medium2026-08-11
CVE-2026-12051 NULL pointer dereference in USB DFU device_next download handler (handle_download) CWE-476 4.6 Medium2026-08-11
CVE-2026-11894 Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error paths CWE-415 5.9 Medium2026-08-11
CVE-2026-11985 Cross-thread FPU register leak on ARM when FPU enabled without register sharing CWE-200 3.6 Low2026-08-11
CVE-2026-11893 Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb) CWE-415 5.9 Medium2026-08-11
CVE-2026-11812 UpdateHub: race condition on shared context causes out-of-bounds write and DoS CWE-362 2.5 Low2026-08-10
CVE-2026-11811 Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS CWE-772 3.7 Low2026-08-10
CVE-2026-8718 Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLS CWE-787 8.4 High2026-08-10
CVE-2026-11809 UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata CWE-125 3.7 Low2026-08-10
CVE-2026-11810 NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS) CWE-476 7.5 High2026-08-10
CVE-2026-11743 Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write CWE-125 6.6 Medium2026-08-07
CVE-2026-11742 Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock CWE-416 3.6 Low2026-08-07
CVE-2026-11368 Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer CWE-416 7.1 High2026-08-04
CVE-2026-10849 Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body CWE-122 8.2 High2026-08-03
CVE-2026-10848 Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg) CWE-125 7.0 High2026-08-02
CVE-2026-10774 PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS CWE-401 2.4 Low2026-08-02
CVE-2026-10773 Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name) CWE-125 5.4 Medium2026-08-01

All 211 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.