VendorsZephyrprojectzephyrall versions
Vulnerabilities

Zephyrproject Zephyr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2026-1679
net: eswifi socket send payload length not bounded
Published 2026-03-27 · Analyzed
7.8EPSS 0.002
CVE-2021-3434
L2CAP: Stack based buffer overflow in le_ecred_conn_req()
Published 2022-06-28 · Modified
7.8EPSS 0.002
CVE-2026-10669
Xtensa MPU `arch_buffer_validate()` integer-overflow lets a user thread bypass syscall pointer validation
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2026-10682
Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace
Published 2026-07-27 · Analyzed
7.8EPSS 0.002
CVE-2026-5071
can: Local Denial of Service via SocketCAN Send
Published 2026-05-30 · Analyzed
7.8EPSS 0.002
CVE-2026-10667
SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads
Published 2026-07-12 · Analyzed
7.8EPSS 0.001
CVE-2023-0779
net: shell: Improper input validation
Published 2023-05-30 · Modified
7.7EPSS 0.005
CVE-2024-6259
BT: HCI: adv_ext_report Improper discarding in adv_ext_report
Published 2024-09-13 · Modified
7.6EPSS 0.006
CVE-2024-6137
BT: Classic: SDP OOB access in get_att_search_list
Published 2024-09-13 · Modified
7.6EPSS 0.006
CVE-2024-4785
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
Published 2024-08-19 · Modified
7.6EPSS 0.005
CVE-2024-6135
BT:Classic: Multiple missing buf length checks
Published 2024-09-13 · Analyzed
7.6EPSS 0.004
CVE-2026-10685
Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler
Published 2026-07-31 · Analyzed
7.6EPSS 0.003
CVE-2020-13600
Malformed SPI in response for eswifi can corrupt kernel memory
Published 2021-05-24 · Modified
7.6EPSS 0.002
CVE-2025-10458
Bluetooth: le_conn_rsp does not sanitize CID, MTU, MPS values
Published 2025-09-19 · Analyzed
7.6EPSS 0.002
CVE-2025-7403
Bluetooth: bt_conn_tx_processor unsafe handling
Published 2025-09-19 · Analyzed
7.6EPSS 0.002
CVE-2026-10680
Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow
Published 2026-07-21 · Analyzed
7.6EPSS 0.002
CVE-2020-10063
Remote Denial of Service in CoAP Option Parsing Due To Integer Overflow
Published 2020-06-05 · Modified
7.5EPSS 0.018
CVE-2021-3455
Disconnecting L2CAP channel right after invalid ATT request leads freeze
Published 2021-10-19 · Modified
7.5EPSS 0.011
CVE-2021-3454
Truncated L2CAP K-frame causes assertion failure
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2021-3510
Zephyr JSON decoder incorrectly decodes array of array
Published 2021-10-05 · Modified
7.5EPSS 0.010
CVE-2023-0359
ipv6: Missing ipv6 nullptr-check in handle_ra_input
Published 2023-07-10 · Modified
7.5EPSS 0.009
CVE-2021-3431
BT: Assertion failure on repeated LL_FEATURE_REQ
Published 2022-06-28 · Modified
7.5EPSS 0.009
CVE-2021-3430
BT: Assertion failure on repeated LL_CONNECTION_PARAM_REQ
Published 2022-06-28 · Modified
7.5EPSS 0.009
CVE-2021-3432
BT: Invalid interval in CONNECT_IND leads to Division by Zero
Published 2022-06-28 · Modified
7.5EPSS 0.009
CVE-2026-8023
Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read
Published 2026-06-29 · Modified
7.5EPSS 0.009
CVE-2021-3320
Type Confusion in 802154 ACK Frames Handling
Published 2021-05-24 · Modified
7.5EPSS 0.008
CVE-2025-2962
Infinite loop in dns_copy_qname
Published 2025-06-24 · Analyzed
7.5EPSS 0.006
CVE-2026-10686
Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers
Published 2026-07-31 · Analyzed
7.5EPSS 0.005
CVE-2026-13351
net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets
Published 2026-06-25 · Analyzed
7.5EPSS 0.005
CVE-2023-5563
The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception.
Published 2023-10-12 · Modified
7.5EPSS 0.004
CVE-2024-8798
Bluetooth: classic: avdtp: missing buffer length check
Published 2024-12-15 · Modified
7.5EPSS 0.004
CVE-2026-10638
Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error
Published 2026-06-16 · Modified
7.5EPSS 0.004
CVE-2026-10665
Heap buffer overflow on WireGuard receive path via unbounded incoming packet length
Published 2026-07-12 · Analyzed
7.4EPSS 0.006
CVE-2026-10646
Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation
Published 2026-06-28 · Modified
7.4EPSS 0.004
CVE-2026-10652
Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)
Published 2026-06-30 · Analyzed
7.4EPSS 0.004
CVE-2022-1841
Out-of-bound write in tcp_flags
Published 2022-08-31 · Modified
7.2EPSS 0.006
CVE-2026-10640
Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)
Published 2026-06-16 · Modified
7.1EPSS 0.004
CVE-2026-11368
Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer
Published 2026-08-04 · Analyzed
7.1EPSS 0.003
CVE-2026-10637
Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query
Published 2026-06-16 · Modified
7.1EPSS 0.003
CVE-2026-10651
Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)
Published 2026-06-22 · Modified
7.1EPSS 0.003
← Prev3 / 5Next →