目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

zephyrproject-rtos 厂商漏洞列表 / CVE 中文分析 118

zephyrproject-rtos 厂商相关 118 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Zephyr Project 是一个跨平台的实时操作系统内核,主要面向资源受限的物联网设备,支持多种架构与硬件平台。鉴于其已收录 118 条 CVE,历史漏洞多集中于内存安全缺陷、权限绕过及拒绝服务,部分涉及远程代码执行风险。该项目采用模块化设计以最小化攻击面,并集成硬件安全扩展支持。开发者需关注内核更新以修复已知漏洞,确保嵌入式系统的安全性与稳定性。

上位製品 zephyrproject-rtos: zephyr
CVE IDタイトルCVSS深刻度公開日
CVE-2026-5590 net: ip/tcp: Null pointer dereference can be triggered by a race condition — ZephyrCWE-476 6.4 Medium2026-04-05
CVE-2026-1679 net: eswifi socket send payload length not bounded — ZephyrCWE-120 7.3 High2026-03-27
CVE-2026-4179 stm32: usb: Infinite while loop in Interrupt Handler — ZephyrCWE-835 6.1 Medium2026-03-14
CVE-2026-0849 crypto: ATAES132A response length allows stack buffer overflow — ZephyrCWE-120 3.8 Low2026-03-14
CVE-2026-1678 dns: memory‑safety issue in the DNS name parser — ZephyrCWE-787 9.4 Critical2026-03-05
CVE-2025-12899 net: icmp: Out of bound memory read — ZephyrCWE-843 6.5 Medium2026-01-30
CVE-2025-12035 Bluetooth: Integer Overflow in Bluetooth Classic (BR/EDR) L2CAP — ZephyrCWE-190 6.5 Medium2025-12-15
CVE-2025-9557 Bluetooth: Mesh: Out-of-Bound Write in gen_prov_cont — ZephyrCWE-120 7.6 High2025-11-26
CVE-2025-9558 Bluetooth: Mesh: Out-of-Bound Write in gen_prov_start — ZephyrCWE-120 7.6 High2025-11-26
CVE-2025-9408 Userspace privilege escalation vulnerability on Cortex M — ZephyrCWE-270 8.2 High2025-11-11
CVE-2025-12890 Bluetooth: peripheral: Invalid handling of malformed connection request — ZephyrCWE-703 6.5 Medium2025-11-07
CVE-2025-10456 Bluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requests — ZephyrCWE-190 7.1 High2025-09-19
CVE-2025-10458 Bluetooth: le_conn_rsp does not sanitize CID, MTU, MPS values — ZephyrCWE-130 7.6 High2025-09-19
CVE-2025-7403 Bluetooth: bt_conn_tx_processor unsafe handling — ZephyrCWE-123 7.6 High2025-09-19
CVE-2025-10457 Bluetooth: Out-Of-Context le_conn_rsp Handling — ZephyrCWE-358 4.3 Medium2025-09-19
CVE-2025-2962 Infinite loop in dns_copy_qname — ZephyrCWE-835 8.2 High2025-06-24
CVE-2025-1675 Out of bounds read in dns_copy_qname — ZephyrCWE-125 8.2 High2025-02-25
CVE-2025-1674 Out of bounds read when unpacking DNS answers — ZephyrCWE-125 8.2 High2025-02-25
CVE-2025-1673 Out of bounds read when calling crc16_ansi and strlen in dns_validate_msg — ZephyrCWE-125 8.2 High2025-02-25
CVE-2024-10395 net: lib: http_server: Buffer Under-read — ZephyrCWE-127 8.6 High2025-02-03
CVE-2024-8798 Bluetooth: classic: avdtp: missing buffer length check — ZephyrCWE-122 7.5 High2024-12-15
CVE-2024-11263 arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=y — ZephyrCWE-270 9.4 Critical2024-11-15
CVE-2024-6444 Bluetooth: ots: missing buffer length check — ZephyrCWE-122 6.3 Medium2024-10-04
CVE-2024-6443 zephyr: out-of-bound read in utf8_trunc — ZephyrCWE-125 6.3 Medium2024-10-04
CVE-2024-6442 Bluetooth: ASCS Unchecked tailroom of the response buffer — ZephyrCWE-787 6.3 Medium2024-10-04
CVE-2024-6259 BT: HCI: adv_ext_report Improper discarding in adv_ext_report — ZephyrCWE-787 7.6 High2024-09-13
CVE-2024-6137 BT: Classic: SDP OOB access in get_att_search_list — ZephyrCWE-121 7.6 High2024-09-13
CVE-2024-6135 BT:Classic: Multiple missing buf length checks — ZephyrCWE-122 7.6 High2024-09-13
CVE-2024-5931 BT: Unchecked user input in bap_broadcast_assistant — ZephyrCWE-1284 6.3 Medium2024-09-13
CVE-2024-6258 BT: Missing length checks of net_buf in rfcomm_handle_data — ZephyrCWE-122 6.8 Medium2024-09-13

本页汇总了 zephyrproject-rtos 厂商截至目前公开的全部 118 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。