Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zephyrproject — Vulnerabilities & Security Advisories 100

Browse all 100 CVE security advisories affecting zephyrproject. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page documents Common Vulnerabilities and Exposures (CVEs) associated with the zephyrproject vendor in the context of open-source operating system weaknesses. It aggregates security issues affecting Zephyr, a real-time operating system (RTOS) designed for resource-constrained and connected IoT devices. The database collects vulnerability records spanning from the earliest disclosed issues in 2017 to the most recent updates in 2024. This comprehensive timeline captures the evolution of security risks within the Zephyr codebase as it matured and gained widespread adoption across various hardware platforms. The scope includes flaws related to buffer overflows, race conditions, improper access controls, and other common software defects identified by the Open Source Security Foundation (OpenSSF) and other security researchers. Users can utilize this resource to track vendor advisories issued by the Zephyr project maintainers, providing insight into how critical flaws are disclosed and patched over time. Additionally, the page serves as a reference for understanding specific weakness classes within real-time embedded environments, highlighting patterns in code quality and security practices. Visitors may also look up a product's vulnerability history to assess the security posture of systems relying on Zephyr RTOS. By reviewing these aggregated data points, developers and security analysts can better evaluate risk exposure and implement appropriate mitigation strategies for their IoT deployments.

Top products by zephyrproject: zephyr
CVE ID Title CVSS Severity Published
CVE-2026-10673 Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly — zephyr CWE-787 8.3 High 2026-07-15
CVE-2026-10672 Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI) — zephyr CWE-125 8.2 High 2026-07-14
CVE-2026-10671 User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`) — zephyr CWE-825 7.1 High 2026-07-14
CVE-2026-10670 User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier — zephyr CWE-476 5.5 Medium 2026-07-14
CVE-2026-10669 Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation — zephyr CWE-787 7.8 High 2026-07-14
CVE-2026-10667 SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads — zephyr CWE-416 7.8 High 2026-07-12
CVE-2026-10668 Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver — zephyr CWE-400 2.4 Low 2026-07-12
CVE-2026-10666 Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c` — zephyr CWE-121 8.1 High 2026-07-12
CVE-2026-10665 Heap buffer overflow on WireGuard receive path via unbounded incoming packet length — zephyr CWE-787 7.4 High 2026-07-12
CVE-2026-10663 Use-after-free / double-free of the root USB device in the experimental USB host stack — zephyr CWE-416 6.1 Medium 2026-07-12
CVE-2026-10664 Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count) — zephyr CWE-787 5.0 Medium 2026-07-12
CVE-2026-10660 Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption — zephyr CWE-787 6.4 Medium 2026-07-11
CVE-2026-10659 NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume — zephyr CWE-476 4.7 Medium 2026-07-07
CVE-2026-10657 Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL) — zephyr CWE-125 3.7 Low 2026-07-05
CVE-2026-10656 NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers — zephyr CWE-476 4.6 Medium 2026-07-05
CVE-2026-10655 Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it — zephyr CWE-416 6.5 Medium 2026-06-30
CVE-2026-10654 RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic — zephyr CWE-362 3.1 Low 2026-06-30
CVE-2026-10653 Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref — zephyr CWE-415 6.4 Medium 2026-06-30
CVE-2026-9263 Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets — zephyr CWE-125 6.5 Medium 2026-06-30
CVE-2026-10652 Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`) — zephyr CWE-125 4.8 Medium 2026-06-30
CVE-2026-10648 NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion — zephyr CWE-476 6.2 Medium 2026-06-29
CVE-2026-8023 Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read — zephyr CWE-22 7.5 High 2026-06-29
CVE-2026-7656 Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack — zephyr CWE-290 8.1 High 2026-06-29
CVE-2026-10647 Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure — zephyr CWE-833 5.3 Medium 2026-06-29
CVE-2026-10593 Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling — zephyr CWE-476 6.5 Medium 2026-06-28
CVE-2026-10646 Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation — zephyr CWE-416 7.4 High 2026-06-28
CVE-2026-10644 Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer — zephyr CWE-787 4.2 Medium 2026-06-28
CVE-2026-10643 Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check) — zephyr CWE-787 8.7 High 2026-06-27
CVE-2026-10642 Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control — zephyr CWE-835 4.6 Medium 2026-06-24
CVE-2026-10658 Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validation — zephyr CWE-787 7.1 High 2026-06-22

This page lists every published CVE security advisory associated with zephyrproject. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.