Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zephyrproject — Vulnerabilities & Security Advisories 95

Browse all 95 CVE security advisories affecting zephyrproject. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page documents Common Vulnerabilities and Exposures (CVEs) associated with the zephyrproject vendor in the context of open-source operating system weaknesses. It aggregates security issues affecting Zephyr, a real-time operating system (RTOS) designed for resource-constrained and connected IoT devices. The database collects vulnerability records spanning from the earliest disclosed issues in 2017 to the most recent updates in 2024. This comprehensive timeline captures the evolution of security risks within the Zephyr codebase as it matured and gained widespread adoption across various hardware platforms. The scope includes flaws related to buffer overflows, race conditions, improper access controls, and other common software defects identified by the Open Source Security Foundation (OpenSSF) and other security researchers. Users can utilize this resource to track vendor advisories issued by the Zephyr project maintainers, providing insight into how critical flaws are disclosed and patched over time. Additionally, the page serves as a reference for understanding specific weakness classes within real-time embedded environments, highlighting patterns in code quality and security practices. Visitors may also look up a product's vulnerability history to assess the security posture of systems relying on Zephyr RTOS. By reviewing these aggregated data points, developers and security analysts can better evaluate risk exposure and implement appropriate mitigation strategies for their IoT deployments.

Top products by zephyrproject: zephyr
CVE ID Title CVSS Severity Published
CVE-2026-11811 Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS — zephyr CWE-772 3.7 Low 2026-08-10
CVE-2026-8718 Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLS — zephyr CWE-787 8.4 High 2026-08-10
CVE-2026-11809 UpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadata — zephyr CWE-125 3.7 Low 2026-08-10
CVE-2026-11810 NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS) — zephyr CWE-476 7.5 High 2026-08-10
CVE-2026-11743 Missing negative-offset/overflow check in SF32LB MPI QSPI NOR flash driver allows out-of-bounds read and write — zephyr CWE-125 6.6 Medium 2026-08-07
CVE-2026-11742 Use-after-free race in kernel `k_queue_peek_head/tail` due to missing spinlock — zephyr CWE-416 3.6 Low 2026-08-07
CVE-2026-11368 Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer — zephyr CWE-416 7.1 High 2026-08-04
CVE-2026-10849 Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body — zephyr CWE-122 8.2 High 2026-08-03
CVE-2026-10848 Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg) — zephyr CWE-125 7.0 High 2026-08-02
CVE-2026-10774 PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS — zephyr CWE-401 2.4 Low 2026-08-02
CVE-2026-10773 Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name) — zephyr CWE-125 5.4 Medium 2026-08-01
CVE-2026-2411 Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values — zephyr CWE-863 6.5 Medium 2026-08-01
CVE-2026-10686 Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers — zephyr CWE-835 5.8 Medium 2026-07-31
CVE-2026-10685 Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler — zephyr CWE-416 7.6 High 2026-07-31
CVE-2026-10684 Out-of-bounds read in coredump shell when printing stored-dump target code — zephyr CWE-125 3.0 Low 2026-07-29
CVE-2026-10683 DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS) — zephyr CWE-835 2.4 Low 2026-07-27
CVE-2026-10682 Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace — zephyr CWE-787 6.6 Medium 2026-07-27
CVE-2026-10681 SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot — zephyr CWE-362 6.5 Medium 2026-07-25
CVE-2026-7007 Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image — zephyr CWE-369 4.6 Medium 2026-07-24
CVE-2026-10680 Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow — zephyr CWE-125 7.6 High 2026-07-21
CVE-2026-10679 Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS) — zephyr CWE-369 3.3 Low 2026-07-21
CVE-2026-10677 Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool — zephyr CWE-401 6.5 Medium 2026-07-21
CVE-2026-10678 NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller — zephyr CWE-476 8.1 High 2026-07-21
CVE-2026-10675 Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS) — zephyr CWE-400 4.3 Medium 2026-07-21
CVE-2026-10674 DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled — zephyr CWE-617 5.5 Medium 2026-07-21
CVE-2026-10673 Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly — zephyr CWE-787 8.3 High 2026-07-15
CVE-2026-10672 Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI) — zephyr CWE-125 8.2 High 2026-07-14
CVE-2026-10671 User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`) — zephyr CWE-825 7.1 High 2026-07-14
CVE-2026-10670 User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier — zephyr CWE-476 5.5 Medium 2026-07-14
CVE-2026-10669 Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation — zephyr CWE-787 7.8 High 2026-07-14

This page lists every published CVE security advisory associated with zephyrproject. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.