VendorsZephyrprojectzephyrany version
Vulnerabilities

Zephyrproject Zephyr any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

166CVEs
CVE-2024-6135
BT:Classic: Multiple missing buf length checks
Published 2024-09-13 · Analyzed
7.6EPSS 0.004
CVE-2026-10685
Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler
Published 2026-07-31 · Analyzed
7.6EPSS 0.003
CVE-2020-13600
Malformed SPI in response for eswifi can corrupt kernel memory
Published 2021-05-24 · Modified
7.6EPSS 0.002
CVE-2025-10458
Bluetooth: le_conn_rsp does not sanitize CID, MTU, MPS values
Published 2025-09-19 · Analyzed
7.6EPSS 0.002
CVE-2025-7403
Bluetooth: bt_conn_tx_processor unsafe handling
Published 2025-09-19 · Analyzed
7.6EPSS 0.002
CVE-2026-10680
Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow
Published 2026-07-21 · Analyzed
7.6EPSS 0.002
CVE-2020-10063
Remote Denial of Service in CoAP Option Parsing Due To Integer Overflow
Published 2020-06-05 · Modified
7.5EPSS 0.018
CVE-2021-3455
Disconnecting L2CAP channel right after invalid ATT request leads freeze
Published 2021-10-19 · Modified
7.5EPSS 0.011
CVE-2021-3454
Truncated L2CAP K-frame causes assertion failure
Published 2021-10-19 · Modified
7.5EPSS 0.010
CVE-2023-0359
ipv6: Missing ipv6 nullptr-check in handle_ra_input
Published 2023-07-10 · Modified
7.5EPSS 0.009
CVE-2021-3431
BT: Assertion failure on repeated LL_FEATURE_REQ
Published 2022-06-28 · Modified
7.5EPSS 0.009
CVE-2021-3430
BT: Assertion failure on repeated LL_CONNECTION_PARAM_REQ
Published 2022-06-28 · Modified
7.5EPSS 0.009
CVE-2021-3432
BT: Invalid interval in CONNECT_IND leads to Division by Zero
Published 2022-06-28 · Modified
7.5EPSS 0.009
CVE-2026-8023
Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read
Published 2026-06-29 · Modified
7.5EPSS 0.009
CVE-2021-3320
Type Confusion in 802154 ACK Frames Handling
Published 2021-05-24 · Modified
7.5EPSS 0.008
CVE-2025-2962
Infinite loop in dns_copy_qname
Published 2025-06-24 · Analyzed
7.5EPSS 0.006
CVE-2026-10686
Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers
Published 2026-07-31 · Analyzed
7.5EPSS 0.005
CVE-2026-13351
net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets
Published 2026-06-25 · Analyzed
7.5EPSS 0.005
CVE-2023-5563
The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception.
Published 2023-10-12 · Modified
7.5EPSS 0.004
CVE-2024-8798
Bluetooth: classic: avdtp: missing buffer length check
Published 2024-12-15 · Modified
7.5EPSS 0.004
CVE-2026-10638
Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error
Published 2026-06-16 · Modified
7.5EPSS 0.004
CVE-2026-10646
Use-after-return in `zsock_getaddrinfo()` when a timed-out DNS query is retried without cancellation
Published 2026-06-28 · Modified
7.4EPSS 0.004
CVE-2026-10652
Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)
Published 2026-06-30 · Analyzed
7.4EPSS 0.004
CVE-2022-1841
Out-of-bound write in tcp_flags
Published 2022-08-31 · Modified
7.2EPSS 0.006
CVE-2026-10640
Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)
Published 2026-06-16 · Modified
7.1EPSS 0.004
CVE-2026-11368
Use-after-free in Bluetooth host ATT TX completion on disconnect mid-transfer
Published 2026-08-04 · Analyzed
7.1EPSS 0.003
CVE-2026-10637
Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query
Published 2026-06-16 · Modified
7.1EPSS 0.003
CVE-2026-10651
Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)
Published 2026-06-22 · Modified
7.1EPSS 0.003
CVE-2026-10658
Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validation
Published 2026-06-22 · Modified
7.1EPSS 0.003
CVE-2026-10641
Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)
Published 2026-06-17 · Modified
7.1EPSS 0.003
CVE-2025-10456
Bluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requests
Published 2025-09-19 · Analyzed
7.1EPSS 0.002
CVE-2026-10671
User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`)
Published 2026-07-14 · Analyzed
7.1EPSS 0.002
CVE-2026-10681
SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot
Published 2026-07-25 · Analyzed
7.0EPSS 0.001
CVE-2023-4265
Buffer overflow in Zephyr USB
Published 2023-08-12 · Modified
6.8EPSS 0.008
CVE-2024-3077
Bluetooth: integer underflow in gatt_find_info_rsp
Published 2024-03-29 · Analyzed
6.8EPSS 0.005
CVE-2024-6258
BT: Missing length checks of net_buf in rfcomm_handle_data
Published 2024-09-13 · Modified
6.8EPSS 0.004
CVE-2023-0396
Buffer Overreads in Bluetooth HCI
Published 2023-01-19 · Modified
6.8EPSS 0.004
CVE-2024-6443
zephyr: out-of-bound read in utf8_trunc
Published 2024-10-04 · Analyzed
6.5EPSS 0.006
CVE-2021-3322
Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr
Published 2021-10-12 · Modified
6.5EPSS 0.005
CVE-2020-10068
Zephyr Bluetooth DLE duplicate requests vulnerability
Published 2020-06-05 · Modified
6.5EPSS 0.005
← Prev3 / 5Next →