Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

zephyr — Vulnerabilities & Security Advisories 264

All 264 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Zephyr real-time operating system, focusing on security weaknesses such as buffer overflows, use-after-free errors, and privilege escalation flaws. It collects publicly disclosed security advisories and bug reports related to the Zephyr project, covering the time range from its initial public releases through recent kernel and subsystem updates. Here, users can track the vendor's published advisories, analyze specific weakness classes like out-of-bounds writes or race conditions, and review the complete vulnerability history of the product to assess risk trends. The dataset includes both critical and high-severity issues identified by the Zephyr security team and external researchers. No specific CVE identifiers are listed individually in the summary view; instead, the page provides a consolidated overview that supports security monitoring, compliance auditing, and patch prioritization for embedded systems developers.

Vendor: zephyrproject-rtos

CVE ID Title CVSS Severity Published
CVE-2026-10647 Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure CWE-833 5.3 Medium 2026-06-29
CVE-2026-10593 Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling CWE-476 6.5 Medium 2026-06-28
CVE-2026-10646 Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation CWE-416 7.4 High 2026-06-28
CVE-2026-10644 Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer CWE-787 4.2 Medium 2026-06-28
CVE-2026-10643 Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check) CWE-787 8.7 High 2026-06-27
CVE-2026-13351 net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets CWE-772 7.5 High 2026-06-25
CVE-2026-10642 Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control CWE-835 4.6 Medium 2026-06-24
CVE-2026-10658 Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validation CWE-787 7.1 High 2026-06-22
CVE-2026-10651 Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`) CWE-20 7.1 High 2026-06-22
CVE-2026-10645 Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image CWE-125 4.9 Medium 2026-06-22
CVE-2026-10641 Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values) CWE-787 7.1 High 2026-06-17
CVE-2026-10640 Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`) CWE-416 4.2 Medium 2026-06-16
CVE-2026-10639 Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()` CWE-416 4.8 Medium 2026-06-16
CVE-2026-10638 Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error CWE-416 5.9 Medium 2026-06-16
CVE-2026-10637 Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query CWE-416 5.9 Medium 2026-06-16
CVE-2026-10636 Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`) CWE-416 3.7 Low 2026-06-16
CVE-2026-10635 Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-init CWE-416 6.3 Medium 2026-06-16
CVE-2026-10634 Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callback CWE-416 4.8 Medium 2026-06-15
CVE-2026-5068 bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data CWE-787 7.6 High 2026-06-09
CVE-2026-5067 Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Key CWE-170 9.8 Critical 2026-06-09
CVE-2026-5066 net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect function CWE-787 6.3 Medium 2026-06-04
CVE-2026-5589 Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem. CWE-787 - - 2026-06-04
CVE-2026-5071 can: Local Denial of Service via SocketCAN Send CWE-125 6.1 Medium 2026-05-30
CVE-2026-5072 ptp: Potential Denial of Service via PTP Interval Shift - - 2026-05-22
CVE-2026-1681 net: Stack Overflow with Ping (to own IP Address) via Shell CWE-674 6.1 Medium 2026-05-12
CVE-2026-1677 net: TLS 1.2 connections allowed on TLS 1.3 sockets CWE-757 5.3 Medium 2026-05-11
CVE-2026-5590 net: ip/tcp: Null pointer dereference can be triggered by a race condition CWE-476 6.4 Medium 2026-04-05
CVE-2026-1679 net: eswifi socket send payload length not bounded CWE-120 7.3 High 2026-03-27
CVE-2026-4179 stm32: usb: Infinite while loop in Interrupt Handler CWE-835 6.1 Medium 2026-03-14
CVE-2026-0849 crypto: ATAES132A response length allows stack buffer overflow CWE-120 3.8 Low 2026-03-14

All 264 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.