Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zephyr — Vulnerabilities & Security Advisories 207

All 207 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities in Zephyr, an open-source real-time operating system for resource-constrained embedded systems, categorized under common weakness types such as buffer overflows and improper input validation. The collection includes security advisories, flaw reports, and associated technical details ranging from initial public disclosures through to recent updates in the current development cycle, ensuring coverage of both legacy issues and newly identified risks within the Zephyr codebase and its associated components. By reviewing this aggregation, you can track vendor advisories for Zephyr to stay informed about critical patches and mitigation strategies, gain a deeper understanding of specific weakness classes that frequently affect embedded RTOS environments, and investigate a product’s vulnerability history to assess long-term security trends and patch responsiveness. This resource is designed to assist security researchers, developers, and system integrators in evaluating the security posture of Zephyr-based deployments, identifying potential attack surfaces, and aligning internal security protocols with upstream fixes. It serves as a centralized reference for correlating reported flaws with their underlying causes and recommended remediations, facilitating more robust risk management decisions for projects relying on this operating system.

Vendor: zephyrproject-rtos

CVE IDTitleCVSSSeverityPublished
CVE-2026-10683 DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS) CWE-835 2.4 Low2026-07-27
CVE-2026-10682 Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace CWE-787 6.6 Medium2026-07-27
CVE-2026-10681 SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot CWE-362 6.5 Medium2026-07-25
CVE-2026-7007 Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image CWE-369 4.6 Medium2026-07-24
CVE-2026-10680 Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow CWE-125 7.6 High2026-07-21
CVE-2026-10679 Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS) CWE-369 3.3 Low2026-07-21
CVE-2026-10677 Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool CWE-401 6.5 Medium2026-07-21
CVE-2026-10678 NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller CWE-476 8.1 High2026-07-21
CVE-2026-10675 Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS) CWE-400 4.3 Medium2026-07-21
CVE-2026-10674 DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled CWE-617 5.5 Medium2026-07-21
CVE-2026-10673 Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly CWE-787 8.3 High2026-07-15
CVE-2026-10672 Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI) CWE-125 8.2 High2026-07-14
CVE-2026-10671 User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`) CWE-825 7.1 High2026-07-14
CVE-2026-10670 User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier CWE-476 5.5 Medium2026-07-14
CVE-2026-10669 Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation CWE-787 7.8 High2026-07-14
CVE-2026-10668 Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver CWE-400 2.4 Low2026-07-12
CVE-2026-10667 SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads CWE-416 7.8 High2026-07-12
CVE-2026-10666 Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c` CWE-121 8.1 High2026-07-12
CVE-2026-10665 Heap buffer overflow on WireGuard receive path via unbounded incoming packet length CWE-787 7.4 High2026-07-12
CVE-2026-10664 Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count) CWE-787 5.0 Medium2026-07-12
CVE-2026-10663 Use-after-free / double-free of the root USB device in the experimental USB host stack CWE-416 6.1 Medium2026-07-12
CVE-2026-10660 Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption CWE-787 6.4 Medium2026-07-11
CVE-2026-10659 NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume CWE-476 4.7 Medium2026-07-07
CVE-2026-10657 Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL) CWE-125 3.7 Low2026-07-05
CVE-2026-10656 NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers CWE-476 4.6 Medium2026-07-05
CVE-2026-10655 Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it CWE-416 6.5 Medium2026-06-30
CVE-2026-10654 RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic CWE-362 3.1 Low2026-06-30
CVE-2026-10653 Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref CWE-415 6.4 Medium2026-06-30
CVE-2026-9263 Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets CWE-125 6.5 Medium2026-06-30
CVE-2026-10652 Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`) CWE-125 4.8 Medium2026-06-30

All 207 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.