Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

zephyr — Vulnerabilities & Security Advisories 264

All 264 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Zephyr real-time operating system, focusing on security weaknesses such as buffer overflows, use-after-free errors, and privilege escalation flaws. It collects publicly disclosed security advisories and bug reports related to the Zephyr project, covering the time range from its initial public releases through recent kernel and subsystem updates. Here, users can track the vendor's published advisories, analyze specific weakness classes like out-of-bounds writes or race conditions, and review the complete vulnerability history of the product to assess risk trends. The dataset includes both critical and high-severity issues identified by the Zephyr security team and external researchers. No specific CVE identifiers are listed individually in the summary view; instead, the page provides a consolidated overview that supports security monitoring, compliance auditing, and patch prioritization for embedded systems developers.

Vendor: zephyrproject-rtos

CVE ID Title CVSS Severity Published
CVE-2026-14367 I3C IBI work-node free-list data race between ISR and workqueue thread CWE-362 3.1 Low 2026-08-31
CVE-2026-14366 SiWx91x WiFi driver double-unref / use-after-free of caller-owned TX net_pkt CWE-416 6.4 Medium 2026-08-31
CVE-2026-13735 WireGuard keepalive transport-data messages accepted without Poly1305 authentication CWE-290 3.7 Low 2026-08-28
CVE-2026-13734 Zephyr WireGuard mutates peer state before anti-replay check, enabling capture-replay endpoint hijack CWE-294 6.5 Medium 2026-08-28
CVE-2026-13481 Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP CWE-125 5.4 Medium 2026-08-26
CVE-2026-13480 Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handler CWE-20 3.1 Low 2026-08-26
CVE-2026-13479 Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler CWE-125 3.1 Low 2026-08-26
CVE-2026-13478 Out-of-bounds read in Zephyr ext2 block-bitmap validation from a crafted s_blocks_count CWE-125 5.5 Medium 2026-08-25
CVE-2026-13217 NULL-pointer dereference in Zephyr OCPP CALLRESULT parsing via unchecked strtok_r/atoi CWE-476 5.9 Medium 2026-08-25
CVE-2026-13216 Out-of-bounds stack write in Zephyr virtio PCI driver from unvalidated device-supplied capability length CWE-787 6.1 Medium 2026-08-25
CVE-2026-13215 Zephyr ext2 mount: unvalidated superblock block size causes out-of-bounds write from a crafted filesystem image CWE-787 6.8 Medium 2026-08-25
CVE-2026-13214 Stack buffer overflow in OCPP GetConfiguration key parsing CWE-787 9.8 Critical 2026-08-25
CVE-2026-13213 Bluetooth HAS: NULL-pointer dereference DoS when a bonded peer reconnects before bt_has_register CWE-476 5.3 Medium 2026-08-24
CVE-2026-13212 Zephyr virtio driver calls an arbitrary function pointer from an out-of-range used-ring descriptor id CWE-129 8.8 High 2026-08-24
CVE-2026-13343 Uninitialised stack memory disclosure in the MIDI 2.0 UMP Stream responder CWE-200 5.3 Medium 2026-08-24
CVE-2026-9728 TOCTOU race in mbox_send syscall verifier allows userspace to leak kernel memory CWE-367 6.4 Medium 2026-08-24
CVE-2026-12999 Infineon Airoc Wi-Fi driver leaks TX buffers on send failure, leading to permanent pool exhaustion CWE-401 5.3 Medium 2026-08-22
CVE-2026-12634 Out-of-bounds stack write in the settings NVS backend from over-reported nvs_read length CWE-787 5.3 Medium 2026-08-19
CVE-2026-12522 Stack buffer overflow in Zephyr hl7800 modem driver parsing network-supplied +CGCONTRDP address fields CWE-787 8.8 High 2026-08-19
CVE-2026-12633 Out-of-bounds write in IPv6 6LoWPAN Context Option handling via unauthenticated Router Advertisement CWE-787 8.1 High 2026-08-19
CVE-2026-12632 Out-of-bounds read in Zephyr PTP message parsing from unvalidated message type CWE-125 6.5 Medium 2026-08-18
CVE-2026-12631 Broken access-control denial in k_thread_join/k_thread_abort syscall validation in Zephyr kernel CWE-862 6.5 Medium 2026-08-18
CVE-2026-12520 Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlers CWE-787 6.4 Medium 2026-08-18
CVE-2026-12519 Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsing CWE-787 5.0 Medium 2026-08-17
CVE-2026-9771 Missing device-pointer validation in flash_copy() syscall allows userspace privilege escalation CWE-822 8.8 High 2026-08-17
CVE-2026-12630 6LoWPAN IPHC uncompression out-of-bounds read on reserved destination addressing mode CWE-125 4.3 Medium 2026-08-17
CVE-2026-12629 PL011 UART error interrupts never cleared, enabling an external-peer interrupt-storm denial of service CWE-835 4.6 Medium 2026-08-17
CVE-2026-12366 Use-after-free freeing an armed dynamically-allocated k_timer in Zephyr userspace object disposal CWE-416 8.8 High 2026-08-14
CVE-2026-12365 Use-after-free in Zephyr delayable work-queue cancellation under SMP timing race CWE-416 5.8 Medium 2026-08-14
CVE-2026-12364 Missing user-space pointer validation in logging syscall z_log_msg_static_create allows kernel memory disclosure and denial of service CWE-822 8.4 High 2026-08-14

All 264 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.