Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

zephyr — Vulnerabilities & Security Advisories 264

All 264 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Zephyr real-time operating system, focusing on security weaknesses such as buffer overflows, use-after-free errors, and privilege escalation flaws. It collects publicly disclosed security advisories and bug reports related to the Zephyr project, covering the time range from its initial public releases through recent kernel and subsystem updates. Here, users can track the vendor's published advisories, analyze specific weakness classes like out-of-bounds writes or race conditions, and review the complete vulnerability history of the product to assess risk trends. The dataset includes both critical and high-severity issues identified by the Zephyr security team and external researchers. No specific CVE identifiers are listed individually in the summary view; instead, the page provides a consolidated overview that supports security monitoring, compliance auditing, and patch prioritization for embedded systems developers.

Vendor: zephyrproject-rtos

CVE ID Title CVSS Severity Published
CVE-2026-17053 SMBus callback-removal syscalls accept an unvalidated user pointer, letting user threads manipulate kernel callback state CWE-862 4.4 Medium 2026-10-01
CVE-2026-18747 Integer underflow of net_buf length in the MCUmgr serial (SMP over console) transport leads to out-of-bounds read CWE-125 6.8 Medium 2026-09-28
CVE-2026-18746 NULL pointer dereference in Zephyr LwM2M client when the CoAP Block1 context pool is exhausted CWE-476 5.9 Medium 2026-09-28
CVE-2026-18417 Wild pointer dereference in Zephyr BSD sockets when a TCP listening socket reports an asynchronous error CWE-843 6.5 Medium 2026-09-28
CVE-2026-18416 Out-of-bounds read in CoAP well-known-core Uri-Query href matching (match_path_uri) CWE-125 3.7 Low 2026-09-28
CVE-2026-18415 Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames CWE-787 6.3 Medium 2026-09-28
CVE-2026-18414 Out-of-bounds write in the ADI MAX32 ADC driver due to incorrect adc_sequence buffer size validation CWE-787 7.8 High 2026-09-28
CVE-2026-18413 Out-of-bounds write in the NXP MCUX LPADC ADC driver due to missing adc_sequence buffer size validation CWE-787 7.8 High 2026-09-28
CVE-2026-16513 Missing write validation of user-supplied handle pointer in the RTIO syscall verifier allows arbitrary kernel write CWE-787 7.8 High 2026-09-28
CVE-2026-17054 Out-of-bounds read and permanent loss of Wi-Fi reception in the ESP-hosted SPI driver's frame reassembly CWE-125 5.3 Medium 2026-09-21
CVE-2026-15890 AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thread synchronization CWE-323 5.3 Medium 2026-09-21
CVE-2026-17052 Missing user-pointer validation in tgpio_pin_read_ts_ec syscall handler allows arbitrary supervisor-memory write from userspace CWE-787 7.8 High 2026-09-21
CVE-2026-17051 Out-of-bounds write in the Intel SEDI IPM driver from an unvalidated inbound doorbell length CWE-787 6.0 Medium 2026-09-21
CVE-2026-17050 Double free of the USB host configuration descriptor when device enumeration fails CWE-415 5.7 Medium 2026-09-21
CVE-2026-16515 ICMPv6 error messages sent for multicast-destined packets and non-unique source addresses enable network amplification in Zephyr's IPv6 stack CWE-406 4.7 Medium 2026-09-18
CVE-2026-16514 Out-of-bounds read in gPTP Announce path-trace validation via unvalidated stepsRemoved CWE-125 4.3 Medium 2026-09-18
CVE-2026-16512 Out-of-bounds read in the Zephyr gPTP receive path when handling short Ethernet frames CWE-125 3.1 Low 2026-09-18
CVE-2026-14986 Out-of-bounds write in it51xxx I2C target FIFO ISR on oversized write transaction CWE-787 6.8 Medium 2026-09-14
CVE-2026-16148 Kernel panic in the it82xx2 USB device controller driver via re-initialization of a busy delayable work item CWE-666 4.6 Medium 2026-09-14
CVE-2026-16147 it82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruption CWE-416 6.8 Medium 2026-09-14
CVE-2026-15924 Use-after-free / double-free from unsynchronized concurrent access to the TLS client session cache in Zephyr sockets CWE-416 5.9 Medium 2026-09-14
CVE-2026-15893 Zephyr IPv6 Neighbor Discovery zero reachable time from crafted Router Advertisement causes assertion/DoS CWE-617 6.5 Medium 2026-09-14
CVE-2026-15923 Infinite loop denial of service in Zephyr SDIO byte-I/O from a card-supplied zero max_blk_size CWE-835 4.6 Medium 2026-09-14
CVE-2026-15892 Heap memory leak in mcumgr settings-management handlers on access-hook rejection leads to denial of service CWE-401 5.3 Medium 2026-09-13
CVE-2026-15891 NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gateway CWE-476 7.5 High 2026-09-13
CVE-2026-15461 Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input CWE-843 5.3 Medium 2026-09-10
CVE-2026-15460 Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path CWE-666 5.4 Medium 2026-09-09
CVE-2026-14697 IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of service CWE-401 6.5 Medium 2026-08-31
CVE-2026-14696 Ethernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustion CWE-401 6.5 Medium 2026-08-31
CVE-2026-14368 Off-by-one out-of-bounds NUL write in Zephyr LwM2M JSON string parser CWE-787 5.4 Medium 2026-08-31

All 264 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.