Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zephyr — Vulnerabilities & Security Advisories 188

All 188 CVE vulnerabilities found in zephyr, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the Zephyr real-time operating system, categorized under various common weakness types and associated tags. It compiles a comprehensive list of disclosed issues affecting the Zephyr RTOS, covering vulnerabilities reported from its initial public release through the most recent updates. This collection aims to provide a clear view of the security landscape surrounding the Zephyr project, ensuring that developers and security professionals have access to historical data alongside current findings. By reviewing this aggregated data, users can effectively track a vendor’s or community’s security advisories to stay informed about critical patches and mitigation strategies. The page facilitates a deeper understanding of specific weakness classes, such as buffer overflows, race conditions, or permission misconfigurations, that have historically impacted the Zephyr codebase. Additionally, it allows users to look up a product’s vulnerability history, offering insights into the frequency and nature of past security incidents. This resource is designed to support risk assessment and secure development practices by highlighting recurring security patterns. Rather than providing detailed technical exploits, the focus remains on summarizing the scope and impact of each vulnerability to aid in prioritizing updates and hardening efforts. The information presented is derived from official advisories, public databases, and community reports, ensuring accuracy and relevance for the Zephyr ecosystem.

Vendor: zephyrproject-rtos

CVE IDTitleCVSSSeverityPublished
CVE-2024-8798 Bluetooth: classic: avdtp: missing buffer length check CWE-122 7.5 High2024-12-15
CVE-2024-11263 arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=y CWE-270 9.4 Critical2024-11-15
CVE-2024-6444 Bluetooth: ots: missing buffer length check CWE-122 6.3 Medium2024-10-04
CVE-2024-6443 zephyr: out-of-bound read in utf8_trunc CWE-125 6.3 Medium2024-10-04
CVE-2024-6442 Bluetooth: ASCS Unchecked tailroom of the response buffer CWE-787 6.3 Medium2024-10-04
CVE-2024-6259 BT: HCI: adv_ext_report Improper discarding in adv_ext_report CWE-787 7.6 High2024-09-13
CVE-2024-6137 BT: Classic: SDP OOB access in get_att_search_list CWE-121 7.6 High2024-09-13
CVE-2024-6135 BT:Classic: Multiple missing buf length checks CWE-122 7.6 High2024-09-13
CVE-2024-5931 BT: Unchecked user input in bap_broadcast_assistant CWE-1284 6.3 Medium2024-09-13
CVE-2024-6258 BT: Missing length checks of net_buf in rfcomm_handle_data CWE-122 6.8 Medium2024-09-13
CVE-2024-5754 BT: Encryption procedure host vulnerability CWE-807 8.2 High2024-09-13
CVE-2024-4785 BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero CWE-369 7.6 High2024-08-19
CVE-2024-3332 bt: host/smp: DoS caused by null pointer dereference CWE-476 6.5 Medium2024-07-03
CVE-2024-3077 Bluetooth: integer underflow in gatt_find_info_rsp CWE-126 6.8 Medium2024-03-29
CVE-2023-7060 Missing Security Control in Zephyr OS IP Packet Handling 8.6 High2024-03-15
CVE-2023-6881 fs: fuse: buffer overflow vulnerability in the Zephyr FS CWE-120 7.3 High2024-02-20
CVE-2024-1638 Bluetooth characteristic LESC security requirement not enforced without additional flags CWE-20 8.2 High2024-02-19
CVE-2023-5779 can: out of bounds in remove_rx_filter function CWE-787 4.4 Medium2024-02-18
CVE-2023-6249 ipm: signed to unsigned conversion problem in esp32_ipm_send CWE-704 8.0 High2024-02-18
CVE-2023-6749 Unchecked user input length in the Zephyr Settings Shell CWE-121 8.0 High2024-02-18
CVE-2023-5055 L2CAP: Possible Stack based buffer overflow in le_ecred_reconf_req() CWE-121 8.3 High2023-11-21
CVE-2023-4424 bt: hci: DoS and possible RCE CWE-190 8.3 High2023-11-21
CVE-2023-5139 Potential buffer overflow vulnerability in the Zephyr STM32 Crypto driver CWE-120 4.4 Medium2023-10-26
CVE-2023-5753 Potential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystem CWE-120 6.3 Medium2023-10-24
CVE-2023-4257 Unchecked user input length in the Zephyr WiFi shell module CWE-120 7.6 High2023-10-13
CVE-2023-4263 Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver CWE-120 7.6 High2023-10-13
CVE-2023-5563 Zephyr 安全漏洞 CWE-703 7.1 High2023-10-12
CVE-2023-3725 Potential buffer overflow vulnerability in the Zephyr CANbus subsystem CWE-120 7.6 High2023-10-06
CVE-2023-5184 Potential signed to unsigned conversion errors and buffer overflow vulnerabilities in the Zephyr IPM driver CWE-120 7.0 High2023-09-27
CVE-2023-4260 Potential off-by-one buffer overflow vulnerability in the Zephyr FS subsystem CWE-120 6.3 Medium2023-09-26

All 188 known CVE vulnerabilities affecting zephyr with full Chinese analysis, references, and POCs where available.