← All vendors

zephyrproject

42 known vulnerabilities affecting zephyrproject products.

Products

zephyr 42

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-5067 High 0.6% 9.8 A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTT…
CVE-2026-5068 Medium 0.5% 7.6 A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in t…
CVE-2026-10646 Medium 0.4% 7.4 Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getadd…
CVE-2026-10672 Medium 0.4% 8.2 subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI…
CVE-2026-10673 Medium 0.4% 8.3 The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/et…
CVE-2026-10678 Medium 0.4% 8.1 The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_…
CVE-2026-7656 Medium 0.3% 8.1 The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_inpu…
CVE-2026-10849 Medium 0.3% 8.2 The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body…
CVE-2026-10685 Medium 0.3% 7.6 The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp()…
CVE-2026-11368 Medium 0.3% 7.1 The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-fl…
CVE-2026-10848 Medium 0.3% 7.0 The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in par…
CVE-2026-10669 Medium 0.2% 7.8 On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_va…
CVE-2026-10643 Medium 0.2% 8.7 Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet…
CVE-2026-10680 Medium 0.2% 7.6 The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_c…
CVE-2026-10671 Medium 0.2% 7.1 In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_…
CVE-2026-10653 Low 0.4% 6.4 The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference…
CVE-2026-10652 Low 0.4% 4.8 Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS resp…
CVE-2026-10686 Low 0.3% 5.8 Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrem…
CVE-2026-5066 Low 0.3% 6.3 A potential out-of-bounds write/read exists in the TLS socket connect path of th…
CVE-2026-5072 Low 0.3% 6.5 A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker…
CVE-2026-10773 Low 0.3% 5.4 The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhc…
CVE-2026-10634 Low 0.3% 4.8 Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach…
CVE-2026-10774 Low 0.3% 2.4 Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on e…
CVE-2026-5589 Low 0.3% 6.3 An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation ha…
CVE-2026-10675 Low 0.2% 4.3 In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_…
CVE-2026-10639 Low 0.2% 4.8 In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icm…
CVE-2026-10683 Low 0.2% 2.4 In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target…
CVE-2026-7007 Low 0.2% 4.6 The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk…
CVE-2026-10647 Low 0.2% 5.3 The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignor…
CVE-2026-5590 Low 0.2% 6.4 A race condition during TCP connection teardown can cause tcp_recv() to operate …
CVE-2026-2411 Low 0.2% 6.5 Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attrib…
CVE-2026-5071 Low 0.2% 6.1 The SocketCAN implementation validates the length of a user-provided buffer cont…
CVE-2026-13480 Low 0.2% 3.1 The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package…
CVE-2026-13481 Low 0.2% 5.4 The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandl…
CVE-2026-10682 Low 0.2% 6.6 The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in…
CVE-2026-13479 Low 0.2% 3.1 The LoRaWAN application-layer clock-synchronization service parses downlinks in …
CVE-2026-10670 Low 0.2% 5.5 The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system ca…
CVE-2026-10674 Low 0.1% 5.5 The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UA…
CVE-2026-10677 Low 0.1% 6.5 The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates…
CVE-2026-10659 Low 0.1% 4.7 The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) impleme…
CVE-2026-10679 Low 0.1% 3.3 The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock di…
CVE-2026-10681 Low 0.1% 6.5 In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/us…