zephyrproject
42 known vulnerabilities affecting zephyrproject products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-5067 | High | 0.6% | 9.8 | A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTT… | |
| CVE-2026-5068 | Medium | 0.5% | 7.6 | A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in t… | |
| CVE-2026-10646 | Medium | 0.4% | 7.4 | Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getadd… | |
| CVE-2026-10672 | Medium | 0.4% | 8.2 | subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI… | |
| CVE-2026-10673 | Medium | 0.4% | 8.3 | The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/et… | |
| CVE-2026-10678 | Medium | 0.4% | 8.1 | The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_… | |
| CVE-2026-7656 | Medium | 0.3% | 8.1 | The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_inpu… | |
| CVE-2026-10849 | Medium | 0.3% | 8.2 | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body… | |
| CVE-2026-10685 | Medium | 0.3% | 7.6 | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp()… | |
| CVE-2026-11368 | Medium | 0.3% | 7.1 | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-fl… | |
| CVE-2026-10848 | Medium | 0.3% | 7.0 | The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in par… | |
| CVE-2026-10669 | Medium | 0.2% | 7.8 | On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_va… | |
| CVE-2026-10643 | Medium | 0.2% | 8.7 | Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet… | |
| CVE-2026-10680 | Medium | 0.2% | 7.6 | The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_c… | |
| CVE-2026-10671 | Medium | 0.2% | 7.1 | In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_… | |
| CVE-2026-10653 | Low | 0.4% | 6.4 | The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference… | |
| CVE-2026-10652 | Low | 0.4% | 4.8 | Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS resp… | |
| CVE-2026-10686 | Low | 0.3% | 5.8 | Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrem… | |
| CVE-2026-5066 | Low | 0.3% | 6.3 | A potential out-of-bounds write/read exists in the TLS socket connect path of th… | |
| CVE-2026-5072 | Low | 0.3% | 6.5 | A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker… | |
| CVE-2026-10773 | Low | 0.3% | 5.4 | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhc… | |
| CVE-2026-10634 | Low | 0.3% | 4.8 | Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach… | |
| CVE-2026-10774 | Low | 0.3% | 2.4 | Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on e… | |
| CVE-2026-5589 | Low | 0.3% | 6.3 | An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation ha… | |
| CVE-2026-10675 | Low | 0.2% | 4.3 | In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_… | |
| CVE-2026-10639 | Low | 0.2% | 4.8 | In Zephyr's native IPv4 stack, icmpv4_handle_echo_request() in subsys/net/ip/icm… | |
| CVE-2026-10683 | Low | 0.2% | 2.4 | In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target… | |
| CVE-2026-7007 | Low | 0.2% | 4.6 | The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk… | |
| CVE-2026-10647 | Low | 0.2% | 5.3 | The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignor… | |
| CVE-2026-5590 | Low | 0.2% | 6.4 | A race condition during TCP connection teardown can cause tcp_recv() to operate … | |
| CVE-2026-2411 | Low | 0.2% | 6.5 | Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attrib… | |
| CVE-2026-5071 | Low | 0.2% | 6.1 | The SocketCAN implementation validates the length of a user-provided buffer cont… | |
| CVE-2026-13480 | Low | 0.2% | 3.1 | The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package… | |
| CVE-2026-13481 | Low | 0.2% | 5.4 | The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandl… | |
| CVE-2026-10682 | Low | 0.2% | 6.6 | The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in… | |
| CVE-2026-13479 | Low | 0.2% | 3.1 | The LoRaWAN application-layer clock-synchronization service parses downlinks in … | |
| CVE-2026-10670 | Low | 0.2% | 5.5 | The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system ca… | |
| CVE-2026-10674 | Low | 0.1% | 5.5 | The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UA… | |
| CVE-2026-10677 | Low | 0.1% | 6.5 | The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates… | |
| CVE-2026-10659 | Low | 0.1% | 4.7 | The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) impleme… | |
| CVE-2026-10679 | Low | 0.1% | 3.3 | The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock di… | |
| CVE-2026-10681 | Low | 0.1% | 6.5 | In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/us… |