VendorsZephyrprojectzephyrall versions
Vulnerabilities

Zephyrproject Zephyr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2023-2234
BT HCI host union variant confusion
Published 2023-07-10 · Modified
8.8EPSS 0.005
CVE-2020-10065
Missing Size Checks in Bluetooth HCI over SPI
Published 2021-05-24 · Modified
8.8EPSS 0.005
CVE-2023-4263
Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver
Published 2023-10-13 · Modified
8.8EPSS 0.005
CVE-2026-5066
net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect function
Published 2026-06-04 · Analyzed
8.8EPSS 0.005
CVE-2026-10673
Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly
Published 2026-07-15 · Analyzed
8.8EPSS 0.004
CVE-2023-4424
bt: hci: DoS and possible RCE
Published 2023-11-21 · Modified
8.8EPSS 0.004
CVE-2023-5184
Potential signed to unsigned conversion errors and buffer overflow vulnerabilities in the Zephyr IPM driver
Published 2023-09-27 · Modified
8.8EPSS 0.004
CVE-2021-3581
Buffer Access with Incorrect Length Value in zephyr
Published 2021-10-05 · Modified
8.8EPSS 0.003
CVE-2026-5068
bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data
Published 2026-06-09 · Analyzed
8.8EPSS 0.003
CVE-2026-10643
Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)
Published 2026-06-27 · Modified
8.7EPSS 0.002
CVE-2023-7060
Missing Security Control in Zephyr OS IP Packet Handling
Published 2024-03-15 · Modified
8.6EPSS 0.005
CVE-2023-4258
bt: mesh: vulnerability in provisioning protocol implementation on provisionee side
Published 2023-09-25 · Modified
8.6EPSS 0.005
CVE-2026-10848
Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)
Published 2026-08-02 · Analyzed
8.6EPSS 0.004
CVE-2024-10395
net: lib: http_server: Buffer Under-read
Published 2025-02-03 · Analyzed
8.6EPSS 0.003
CVE-2022-2741
can: denial-of-service can be triggered by a crafted CAN frame
Published 2022-10-31 · Modified
8.2EPSS 0.006
CVE-2026-10849
Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body
Published 2026-08-03 · Analyzed
8.2EPSS 0.005
CVE-2021-3861
The RNDIS USB device class includes a buffer overflow vulnerability
Published 2022-02-07 · Modified
8.2EPSS 0.005
CVE-2025-1674
Out of bounds read when unpacking DNS answers
Published 2025-02-25 · Analyzed
8.2EPSS 0.004
CVE-2025-1673
Out of bounds read when calling crc16_ansi and strlen in dns_validate_msg
Published 2025-02-25 · Analyzed
8.2EPSS 0.004
CVE-2024-5754
BT: Encryption procedure host vulnerability
Published 2024-09-13 · Modified
8.2EPSS 0.003
CVE-2020-10019
Buffer Overflow in USB DFU requested length
Published 2020-05-11 · Modified
8.1EPSS 0.005
CVE-2026-10653
Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref
Published 2026-06-30 · Modified
8.1EPSS 0.004
CVE-2020-10021
Out-of-bounds write in USB Mass Storage with unaligned sizes
Published 2020-05-11 · Modified
8.1EPSS 0.004
CVE-2025-10457
Bluetooth: Out-Of-Context le_conn_rsp Handling
Published 2025-09-19 · Analyzed
8.1EPSS 0.004
CVE-2026-10678
NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller
Published 2026-07-21 · Analyzed
8.1EPSS 0.004
CVE-2026-7656
Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack
Published 2026-06-29 · Modified
8.1EPSS 0.003
CVE-2026-9263
Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets
Published 2026-06-30 · Analyzed
8.1EPSS 0.003
CVE-2020-10060
UpdateHub Might Dereference An Uninitialized Pointer
Published 2020-05-11 · Modified
8.0EPSS 0.016
CVE-2023-1901
HCI send_sync Dangling Semaphore Reference Re-use
Published 2023-07-10 · Modified
8.0EPSS 0.006
CVE-2023-1902
HCI Connection Creation Dangling State Reference Re-use
Published 2023-07-10 · Modified
8.0EPSS 0.006
CVE-2017-14201
The shell DNS command can cause unpredictable results due to misuse of stack variables.
Published 2019-08-29 · Modified
7.8EPSS 0.011
CVE-2020-10027
ARC Platform Uses Signed Integer Comparison When Validating Syscall Numbers
Published 2020-05-11 · Modified
7.8EPSS 0.007
CVE-2020-10024
ARM Platform Uses Signed Integer Comparison When Validating Syscall Numbers
Published 2020-05-11 · Modified
7.8EPSS 0.007
CVE-2017-14202
The shell implementation does not protect against buffer overruns resulting in unpredictable behavior.
Published 2019-08-29 · Modified
7.8EPSS 0.006
CVE-2020-10067
Integer Overflow In is_in_region Allows User Thread To Access Kernel Memory
Published 2020-05-11 · Modified
7.8EPSS 0.004
CVE-2023-5139
Potential buffer overflow vulnerability in the Zephyr STM32 Crypto driver
Published 2023-10-26 · Modified
7.8EPSS 0.004
CVE-2020-10058
Multiple Syscalls In kscan Subsystem Performs No Argument Validation
Published 2020-05-11 · Modified
7.8EPSS 0.004
CVE-2020-10028
Multiple Syscalls In GPIO Subsystem Performs No Argument Validation
Published 2020-05-11 · Modified
7.8EPSS 0.004
CVE-2020-13598
FS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_stat
Published 2021-05-24 · Modified
7.8EPSS 0.002
CVE-2020-13603
Integer Overflow in memory allocating functions
Published 2021-05-24 · Modified
7.8EPSS 0.002
← Prev2 / 5Next →