Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zephyr — Vulnerabilities & Security Advisories 188

All 188 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the Zephyr real-time operating system, categorized under various common weakness types and associated tags. It compiles a comprehensive list of disclosed issues affecting the Zephyr RTOS, covering vulnerabilities reported from its initial public release through the most recent updates. This collection aims to provide a clear view of the security landscape surrounding the Zephyr project, ensuring that developers and security professionals have access to historical data alongside current findings. By reviewing this aggregated data, users can effectively track a vendor’s or community’s security advisories to stay informed about critical patches and mitigation strategies. The page facilitates a deeper understanding of specific weakness classes, such as buffer overflows, race conditions, or permission misconfigurations, that have historically impacted the Zephyr codebase. Additionally, it allows users to look up a product’s vulnerability history, offering insights into the frequency and nature of past security incidents. This resource is designed to support risk assessment and secure development practices by highlighting recurring security patterns. Rather than providing detailed technical exploits, the focus remains on summarizing the scope and impact of each vulnerability to aid in prioritizing updates and hardening efforts. The information presented is derived from official advisories, public databases, and community reports, ensuring accuracy and relevance for the Zephyr ecosystem.

Vendor: zephyrproject-rtos

CVE IDTitleCVSSSeverityPublished
CVE-2026-10663 Use-after-free / double-free of the root USB device in the experimental USB host stack CWE-416 6.1 Medium2026-07-12
CVE-2026-10664 Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count) CWE-787 5.0 Medium2026-07-12
CVE-2026-10660 Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption CWE-787 6.4 Medium2026-07-11
CVE-2026-10659 NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume CWE-476 4.7 Medium2026-07-07
CVE-2026-10657 Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL) CWE-125 3.7 Low2026-07-05
CVE-2026-10656 NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers CWE-476 4.6 Medium2026-07-05
CVE-2026-10655 Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it CWE-416 6.5 Medium2026-06-30
CVE-2026-10654 RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic CWE-362 3.1 Low2026-06-30
CVE-2026-10653 Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref CWE-415 6.4 Medium2026-06-30
CVE-2026-9263 Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets CWE-125 6.5 Medium2026-06-30
CVE-2026-10652 Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`) CWE-125 4.8 Medium2026-06-30
CVE-2026-10648 NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion CWE-476 6.2 Medium2026-06-29
CVE-2026-8023 Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read CWE-22 7.5 High2026-06-29
CVE-2026-7656 Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack CWE-290 8.1 High2026-06-29
CVE-2026-10647 Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure CWE-833 5.3 Medium2026-06-29
CVE-2026-10593 Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling CWE-476 6.5 Medium2026-06-28
CVE-2026-10646 Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation CWE-416 7.4 High2026-06-28
CVE-2026-10644 Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer CWE-787 4.2 Medium2026-06-28
CVE-2026-10643 Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check) CWE-787 8.7 High2026-06-27
CVE-2026-13351 net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets CWE-772 7.5 High2026-06-25
CVE-2026-10642 Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control CWE-835 4.6 Medium2026-06-24
CVE-2026-10658 Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validation CWE-787 7.1 High2026-06-22
CVE-2026-10651 Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`) CWE-20 7.1 High2026-06-22
CVE-2026-10645 Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image CWE-125 4.9 Medium2026-06-22
CVE-2026-10641 Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values) CWE-787 7.1 High2026-06-17
CVE-2026-10640 Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`) CWE-416 4.2 Medium2026-06-16
CVE-2026-10639 Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()` CWE-416 4.8 Medium2026-06-16
CVE-2026-10638 Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error CWE-416 5.9 Medium2026-06-16
CVE-2026-10637 Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query CWE-416 5.9 Medium2026-06-16
CVE-2026-10636 Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`) CWE-416 3.7 Low2026-06-16

All 188 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.