Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zephyr — Vulnerabilities & Security Advisories 198

All 198 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the Zephyr real-time operating system, categorized under various common weakness types and associated tags. It compiles a comprehensive list of disclosed issues affecting the Zephyr RTOS, covering vulnerabilities reported from its initial public release through the most recent updates. This collection aims to provide a clear view of the security landscape surrounding the Zephyr project, ensuring that developers and security professionals have access to historical data alongside current findings. By reviewing this aggregated data, users can effectively track a vendor’s or community’s security advisories to stay informed about critical patches and mitigation strategies. The page facilitates a deeper understanding of specific weakness classes, such as buffer overflows, race conditions, or permission misconfigurations, that have historically impacted the Zephyr codebase. Additionally, it allows users to look up a product’s vulnerability history, offering insights into the frequency and nature of past security incidents. This resource is designed to support risk assessment and secure development practices by highlighting recurring security patterns. Rather than providing detailed technical exploits, the focus remains on summarizing the scope and impact of each vulnerability to aid in prioritizing updates and hardening efforts. The information presented is derived from official advisories, public databases, and community reports, ensuring accuracy and relevance for the Zephyr ecosystem.

Vendor: zephyrproject-rtos

CVE IDTitleCVSSSeverityPublished
CVE-2026-10642 Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control CWE-835 4.6 Medium2026-06-24
CVE-2026-10658 Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validation CWE-787 7.1 High2026-06-22
CVE-2026-10651 Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`) CWE-20 7.1 High2026-06-22
CVE-2026-10645 Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image CWE-125 4.9 Medium2026-06-22
CVE-2026-10641 Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values) CWE-787 7.1 High2026-06-17
CVE-2026-10640 Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`) CWE-416 4.2 Medium2026-06-16
CVE-2026-10639 Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()` CWE-416 4.8 Medium2026-06-16
CVE-2026-10638 Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error CWE-416 5.9 Medium2026-06-16
CVE-2026-10637 Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query CWE-416 5.9 Medium2026-06-16
CVE-2026-10636 Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`) CWE-416 3.7 Low2026-06-16
CVE-2026-10635 Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-init CWE-416 6.3 Medium2026-06-16
CVE-2026-10634 Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callback CWE-416 4.8 Medium2026-06-15
CVE-2026-5068 bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data CWE-787 7.6 High2026-06-09
CVE-2026-5067 Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Key CWE-170 9.8 Critical2026-06-09
CVE-2026-5066 net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect function CWE-787 6.3 Medium2026-06-04
CVE-2026-5589 Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem. CWE-787--2026-06-04
CVE-2026-5071 can: Local Denial of Service via SocketCAN Send CWE-125 6.1 Medium2026-05-30
CVE-2026-5072 ptp: Potential Denial of Service via PTP Interval Shift --2026-05-22
CVE-2026-1681 net: Stack Overflow with Ping (to own IP Address) via Shell CWE-674 6.1 Medium2026-05-12
CVE-2026-1677 net: TLS 1.2 connections allowed on TLS 1.3 sockets CWE-757 5.3 Medium2026-05-11
CVE-2026-5590 net: ip/tcp: Null pointer dereference can be triggered by a race condition CWE-476 6.4 Medium2026-04-05
CVE-2026-1679 net: eswifi socket send payload length not bounded CWE-120 7.3 High2026-03-27
CVE-2026-4179 stm32: usb: Infinite while loop in Interrupt Handler CWE-835 6.1 Medium2026-03-14
CVE-2026-0849 crypto: ATAES132A response length allows stack buffer overflow CWE-120 3.8 Low2026-03-14
CVE-2026-1678 dns: memory‑safety issue in the DNS name parser CWE-787 9.4 Critical2026-03-05
CVE-2025-12899 net: icmp: Out of bound memory read CWE-843 6.5 Medium2026-01-30
CVE-2025-12035 Bluetooth: Integer Overflow in Bluetooth Classic (BR/EDR) L2CAP CWE-190 6.5 Medium2025-12-15
CVE-2025-9557 Bluetooth: Mesh: Out-of-Bound Write in gen_prov_cont CWE-120 7.6 High2025-11-26
CVE-2025-9558 Bluetooth: Mesh: Out-of-Bound Write in gen_prov_start CWE-120 7.6 High2025-11-26
CVE-2025-9408 Userspace privilege escalation vulnerability on Cortex M CWE-270 8.2 High2025-11-11

All 198 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.