Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

zephyr — Vulnerabilities & Security Advisories 264

All 264 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the Zephyr real-time operating system, focusing on security weaknesses such as buffer overflows, use-after-free errors, and privilege escalation flaws. It collects publicly disclosed security advisories and bug reports related to the Zephyr project, covering the time range from its initial public releases through recent kernel and subsystem updates. Here, users can track the vendor's published advisories, analyze specific weakness classes like out-of-bounds writes or race conditions, and review the complete vulnerability history of the product to assess risk trends. The dataset includes both critical and high-severity issues identified by the Zephyr security team and external researchers. No specific CVE identifiers are listed individually in the summary view; instead, the page provides a consolidated overview that supports security monitoring, compliance auditing, and patch prioritization for embedded systems developers.

Vendor: zephyrproject-rtos

CVE ID Title CVSS Severity Published
CVE-2023-7060 Missing Security Control in Zephyr OS IP Packet Handling 8.6 High 2024-03-15
CVE-2023-6881 fs: fuse: buffer overflow vulnerability in the Zephyr FS CWE-120 7.3 High 2024-02-20
CVE-2024-1638 Bluetooth characteristic LESC security requirement not enforced without additional flags CWE-20 8.2 High 2024-02-19
CVE-2023-5779 can: out of bounds in remove_rx_filter function CWE-787 4.4 Medium 2024-02-18
CVE-2023-6249 ipm: signed to unsigned conversion problem in esp32_ipm_send CWE-704 8.0 High 2024-02-18
CVE-2023-6749 Unchecked user input length in the Zephyr Settings Shell CWE-121 8.0 High 2024-02-18
CVE-2023-5055 L2CAP: Possible Stack based buffer overflow in le_ecred_reconf_req() CWE-121 8.3 High 2023-11-21
CVE-2023-4424 bt: hci: DoS and possible RCE CWE-190 8.3 High 2023-11-21
CVE-2023-5139 Potential buffer overflow vulnerability in the Zephyr STM32 Crypto driver CWE-120 4.4 Medium 2023-10-26
CVE-2023-5753 Potential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystem CWE-120 6.3 Medium 2023-10-24
CVE-2023-4257 Unchecked user input length in the Zephyr WiFi shell module CWE-120 7.6 High 2023-10-13
CVE-2023-4263 Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver CWE-120 7.6 High 2023-10-13
CVE-2023-5563 Zephyr 安全漏洞 CWE-703 7.1 High 2023-10-12
CVE-2023-3725 Potential buffer overflow vulnerability in the Zephyr CANbus subsystem CWE-120 7.6 High 2023-10-06
CVE-2023-5184 Potential signed to unsigned conversion errors and buffer overflow vulnerabilities in the Zephyr IPM driver CWE-120 7.0 High 2023-09-27
CVE-2023-4260 Potential off-by-one buffer overflow vulnerability in the Zephyr FS subsystem CWE-120 6.3 Medium 2023-09-26
CVE-2023-4264 Potential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystem CWE-120 7.1 High 2023-09-26
CVE-2023-4259 Potential buffer overflow vulnerabilities in the Zephyr eS-WiFi driver CWE-120 7.1 High 2023-09-25
CVE-2023-4258 bt: mesh: vulnerability in provisioning protocol implementation on provisionee side CWE-684 8.6 High 2023-09-25
CVE-2023-4265 Buffer overflow in Zephyr USB CWE-120 6.4 Medium 2023-08-12
CVE-2023-1901 HCI send_sync Dangling Semaphore Reference Re-use 5.9 Medium 2023-07-10
CVE-2023-2234 BT HCI host union variant confusion CWE-843 6.8 Medium 2023-07-10
CVE-2023-1902 HCI Connection Creation Dangling State Reference Re-use 5.9 Medium 2023-07-10
CVE-2023-0359 ipv6: Missing ipv6 nullptr-check in handle_ra_input CWE-20 5.9 Medium 2023-07-10
CVE-2023-0779 net: shell: Improper input validation CWE-20 6.7 Medium 2023-05-30
CVE-2021-3329 DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer CWE-703 9.6 Critical 2023-02-26
CVE-2022-3806 Bluetooth HCI Error Handling Double Free CWE-415 9.8 - 2023-01-19
CVE-2023-0396 Buffer Overreads in Bluetooth HCI CWE-126 8.8 - 2023-01-19
CVE-2023-0397 DoS: Invalid Initialization in le_read_buffer_size_complete CWE-703 9.6 Critical 2023-01-19
CVE-2021-3966 Usb bluetooth device ACL read cb buffer overflow CWE-122 9.6 Critical 2023-01-11

All 264 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.