VendorsZephyrprojectzephyrany version
Vulnerabilities

Zephyrproject Zephyr any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

166CVEs
CVE-2023-4424
bt: hci: DoS and possible RCE
Published 2023-11-21 · Modified
8.8EPSS 0.004
CVE-2023-5184
Potential signed to unsigned conversion errors and buffer overflow vulnerabilities in the Zephyr IPM driver
Published 2023-09-27 · Modified
8.8EPSS 0.004
CVE-2021-3581
Buffer Access with Incorrect Length Value in zephyr
Published 2021-10-05 · Modified
8.8EPSS 0.003
CVE-2026-5068
bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data
Published 2026-06-09 · Analyzed
8.8EPSS 0.003
CVE-2026-10643
Out-of-bounds heap write in Zephyr `recvmsg()` ancillary-data path (`insert_pktinfo` undersizes the control-buffer capacity check)
Published 2026-06-27 · Modified
8.7EPSS 0.002
CVE-2023-7060
Missing Security Control in Zephyr OS IP Packet Handling
Published 2024-03-15 · Modified
8.6EPSS 0.005
CVE-2023-4258
bt: mesh: vulnerability in provisioning protocol implementation on provisionee side
Published 2023-09-25 · Modified
8.6EPSS 0.005
CVE-2026-10848
Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)
Published 2026-08-02 · Analyzed
8.6EPSS 0.004
CVE-2024-10395
net: lib: http_server: Buffer Under-read
Published 2025-02-03 · Analyzed
8.6EPSS 0.003
CVE-2022-2741
can: denial-of-service can be triggered by a crafted CAN frame
Published 2022-10-31 · Modified
8.2EPSS 0.006
CVE-2026-10849
Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body
Published 2026-08-03 · Analyzed
8.2EPSS 0.005
CVE-2021-3861
The RNDIS USB device class includes a buffer overflow vulnerability
Published 2022-02-07 · Modified
8.2EPSS 0.005
CVE-2025-1674
Out of bounds read when unpacking DNS answers
Published 2025-02-25 · Analyzed
8.2EPSS 0.004
CVE-2025-1673
Out of bounds read when calling crc16_ansi and strlen in dns_validate_msg
Published 2025-02-25 · Analyzed
8.2EPSS 0.004
CVE-2024-5754
BT: Encryption procedure host vulnerability
Published 2024-09-13 · Modified
8.2EPSS 0.003
CVE-2020-10019
Buffer Overflow in USB DFU requested length
Published 2020-05-11 · Modified
8.1EPSS 0.005
CVE-2026-10653
Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref
Published 2026-06-30 · Modified
8.1EPSS 0.004
CVE-2020-10021
Out-of-bounds write in USB Mass Storage with unaligned sizes
Published 2020-05-11 · Modified
8.1EPSS 0.004
CVE-2025-10457
Bluetooth: Out-Of-Context le_conn_rsp Handling
Published 2025-09-19 · Analyzed
8.1EPSS 0.004
CVE-2026-10678
NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller
Published 2026-07-21 · Analyzed
8.1EPSS 0.004
CVE-2026-7656
Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack
Published 2026-06-29 · Modified
8.1EPSS 0.003
CVE-2026-9263
Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets
Published 2026-06-30 · Analyzed
8.1EPSS 0.003
CVE-2020-10060
UpdateHub Might Dereference An Uninitialized Pointer
Published 2020-05-11 · Modified
8.0EPSS 0.016
CVE-2023-1901
HCI send_sync Dangling Semaphore Reference Re-use
Published 2023-07-10 · Modified
8.0EPSS 0.006
CVE-2023-1902
HCI Connection Creation Dangling State Reference Re-use
Published 2023-07-10 · Modified
8.0EPSS 0.006
CVE-2017-14201
The shell DNS command can cause unpredictable results due to misuse of stack variables.
Published 2019-08-29 · Modified
7.8EPSS 0.011
CVE-2017-14202
The shell implementation does not protect against buffer overruns resulting in unpredictable behavior.
Published 2019-08-29 · Modified
7.8EPSS 0.006
CVE-2023-5139
Potential buffer overflow vulnerability in the Zephyr STM32 Crypto driver
Published 2023-10-26 · Modified
7.8EPSS 0.004
CVE-2020-13598
FS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_stat
Published 2021-05-24 · Modified
7.8EPSS 0.002
CVE-2020-13603
Integer Overflow in memory allocating functions
Published 2021-05-24 · Modified
7.8EPSS 0.002
CVE-2026-1679
net: eswifi socket send payload length not bounded
Published 2026-03-27 · Analyzed
7.8EPSS 0.002
CVE-2021-3434
L2CAP: Stack based buffer overflow in le_ecred_conn_req()
Published 2022-06-28 · Modified
7.8EPSS 0.002
CVE-2026-10669
Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2026-5071
can: Local Denial of Service via SocketCAN Send
Published 2026-05-30 · Analyzed
7.8EPSS 0.002
CVE-2026-10682
Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace
Published 2026-07-27 · Analyzed
7.8EPSS 0.002
CVE-2026-10667
SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads
Published 2026-07-12 · Analyzed
7.8EPSS 0.001
CVE-2023-0779
net: shell: Improper input validation
Published 2023-05-30 · Modified
7.7EPSS 0.005
CVE-2024-6259
BT: HCI: adv_ext_report Improper discarding in adv_ext_report
Published 2024-09-13 · Modified
7.6EPSS 0.006
CVE-2024-6137
BT: Classic: SDP OOB access in get_att_search_list
Published 2024-09-13 · Modified
7.6EPSS 0.006
CVE-2024-4785
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
Published 2024-08-19 · Modified
7.6EPSS 0.005
← Prev2 / 5Next →