Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

zephyr — Vulnerabilities & Security Advisories 264

All 264 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Zephyr real-time operating system, focusing on security weaknesses such as buffer overflows, use-after-free errors, and privilege escalation flaws. It collects publicly disclosed security advisories and bug reports related to the Zephyr project, covering the time range from its initial public releases through recent kernel and subsystem updates. Here, users can track the vendor's published advisories, analyze specific weakness classes like out-of-bounds writes or race conditions, and review the complete vulnerability history of the product to assess risk trends. The dataset includes both critical and high-severity issues identified by the Zephyr security team and external researchers. No specific CVE identifiers are listed individually in the summary view; instead, the page provides a consolidated overview that supports security monitoring, compliance auditing, and patch prioritization for embedded systems developers.

Vendor: zephyrproject-rtos

CVE ID Title CVSS Severity Published
CVE-2026-12363 Out-of-bounds write in LoRaWAN fragmented transport from a fragment index of 0 CWE-787 4.2 Medium 2026-08-14
CVE-2026-12236 Infinite loop (DoS) in Bluetooth GATT client parsing of Read-By-Type responses with zero data length CWE-835 6.5 Medium 2026-08-13
CVE-2026-12235 Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787) CWE-787 6.3 Medium 2026-08-12
CVE-2026-12234 TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write CWE-367 7.8 High 2026-08-12
CVE-2026-12233 Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention CWE-665 5.9 Medium 2026-08-12
CVE-2026-12232 Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties CWE-125 6.1 Medium 2026-08-12
CVE-2026-12052 Out-of-bounds write in USB CDC NCM control handler when host wLength is smaller than the response CWE-787 5.2 Medium 2026-08-11
CVE-2026-12051 NULL pointer dereference in USB DFU device_next download handler (handle_download) CWE-476 4.6 Medium 2026-08-11
CVE-2026-11894 Double-free / use-after-free in Realtek BEE Bluetooth HCI driver `send()` error paths CWE-415 5.9 Medium 2026-08-11
CVE-2026-11985 Cross-thread FPU register leak on ARM when FPU enabled without register sharing CWE-200 3.6 Low 2026-08-11
CVE-2026-11893 Double free / use-after-free in Bouffalo Lab HCI driver send() error paths (hci_bflb) CWE-415 5.9 Medium 2026-08-11
CVE-2026-11812 UpdateHub: race condition on shared context causes out-of-bounds write and DoS CWE-362 2.5 Low 2026-08-10
CVE-2026-11811 Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS CWE-772 3.7 Low 2026-08-10
CVE-2026-8718 Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLS CWE-787 8.4 High 2026-08-10
CVE-2026-11809 UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata CWE-125 3.7 Low 2026-08-10
CVE-2026-11810 NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS) CWE-476 7.5 High 2026-08-10
CVE-2026-11742 Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock CWE-416 3.6 Low 2026-08-07
CVE-2026-11743 Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write CWE-125 6.6 Medium 2026-08-07
CVE-2026-11368 Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer CWE-416 7.1 High 2026-08-04
CVE-2026-10849 Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body CWE-122 8.2 High 2026-08-03
CVE-2026-10848 Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg) CWE-125 7.0 High 2026-08-02
CVE-2026-10774 PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS CWE-401 2.4 Low 2026-08-02
CVE-2026-10773 Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name) CWE-125 5.4 Medium 2026-08-01
CVE-2026-2411 Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values CWE-863 6.5 Medium 2026-08-01
CVE-2026-10686 Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers CWE-835 5.8 Medium 2026-07-31
CVE-2026-10685 Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler CWE-416 7.6 High 2026-07-31
CVE-2026-10684 Out-of-bounds read in coredump shell when printing stored-dump target code CWE-125 3.0 Low 2026-07-29
CVE-2026-10683 DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS) CWE-835 2.4 Low 2026-07-27
CVE-2026-10682 Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace CWE-787 6.6 Medium 2026-07-27
CVE-2026-10681 SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot CWE-362 6.5 Medium 2026-07-25

All 264 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.