VendorsZephyrprojectzephyrall versions
Vulnerabilities

Zephyrproject Zephyr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2026-10641
Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)
Published 2026-06-17 · Modified
7.1EPSS 0.003
CVE-2026-10658
Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validation
Published 2026-06-22 · Modified
7.1EPSS 0.003
CVE-2025-10456
Bluetooth: Semi-Arbitrary ability to make the BLE Target send disconnection requests
Published 2025-09-19 · Analyzed
7.1EPSS 0.002
CVE-2026-10671
User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`)
Published 2026-07-14 · Analyzed
7.1EPSS 0.002
CVE-2026-10681
SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot
Published 2026-07-25 · Analyzed
7.0EPSS 0.001
CVE-2020-10023
Shell Subsystem Contains a Buffer Overflow Vulnerability In shell_spaces_trim
Published 2020-05-11 · Modified
6.9EPSS 0.005
CVE-2023-4265
Buffer overflow in Zephyr USB
Published 2023-08-12 · Modified
6.8EPSS 0.008
CVE-2024-3077
Bluetooth: integer underflow in gatt_find_info_rsp
Published 2024-03-29 · Analyzed
6.8EPSS 0.005
CVE-2024-6258
BT: Missing length checks of net_buf in rfcomm_handle_data
Published 2024-09-13 · Modified
6.8EPSS 0.004
CVE-2023-0396
Buffer Overreads in Bluetooth HCI
Published 2023-01-19 · Modified
6.8EPSS 0.004
CVE-2026-0849
crypto: ATAES132A response length allows stack buffer overflow
Published 2026-03-14 · Analyzed
6.8EPSS 0.002
CVE-2025-20696
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09915215; Issue ID: MSV-3801.
Published 2025-08-04 · Analyzed
6.8EPSS 0.001
CVE-2025-20746
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441; Issue ID: MSV-3967.
Published 2025-11-04 · Analyzed
6.7EPSS 0.001
CVE-2025-20747
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443; Issue ID: MSV-3966.
Published 2025-11-04 · Analyzed
6.7EPSS 0.001
CVE-2021-3436
BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known
Published 2021-10-05 · Modified
6.5EPSS 0.010
CVE-2024-6443
zephyr: out-of-bound read in utf8_trunc
Published 2024-10-04 · Analyzed
6.5EPSS 0.006
CVE-2021-3322
Unexpected Pointer Aliasing in IEEE 802154 Fragment Reassembly in Zephyr
Published 2021-10-12 · Modified
6.5EPSS 0.005
CVE-2020-10068
Zephyr Bluetooth DLE duplicate requests vulnerability
Published 2020-06-05 · Modified
6.5EPSS 0.005
CVE-2024-5931
BT: Unchecked user input in bap_broadcast_assistant
Published 2024-09-13 · Modified
6.5EPSS 0.004
CVE-2024-3332
bt: host/smp: DoS caused by null pointer dereference
Published 2024-07-03 · Analyzed
6.5EPSS 0.004
CVE-2026-10675
Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)
Published 2026-07-21 · Analyzed
6.5EPSS 0.004
CVE-2020-10069
Zephyr Bluetooth unchecked packet data results in denial of service
Published 2021-05-24 · Modified
6.5EPSS 0.004
CVE-2026-10655
Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it
Published 2026-06-30 · Analyzed
6.5EPSS 0.004
CVE-2024-6444
Bluetooth: ots: missing buffer length check
Published 2024-10-04 · Analyzed
6.5EPSS 0.003
CVE-2024-6442
Bluetooth: ASCS Unchecked tailroom of the response buffer
Published 2024-10-04 · Analyzed
6.5EPSS 0.003
CVE-2026-5072
ptp: Potential Denial of Service via PTP Interval Shift
Published 2026-05-22 · Analyzed
6.5EPSS 0.003
CVE-2026-10593
Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling
Published 2026-06-28 · Modified
6.5EPSS 0.003
CVE-2026-10774
PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS
Published 2026-08-02 · Analyzed
6.5EPSS 0.003
CVE-2022-0553
Possible to retrieve uncrypted firmware image
Published 2023-01-11 · Modified
6.5EPSS 0.003
CVE-2026-2411
Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values
Published 2026-08-01 · Analyzed
6.5EPSS 0.002
CVE-2026-10677
Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool
Published 2026-07-21 · Analyzed
6.5EPSS 0.001
CVE-2026-5590
net: ip/tcp: Null pointer dereference can be triggered by a race condition
Published 2026-04-05 · Analyzed
6.4EPSS 0.003
CVE-2026-5589
Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem.
Published 2026-06-04 · Analyzed
6.3EPSS 0.004
CVE-2026-10635
Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-init
Published 2026-06-16 · Modified
6.3EPSS 0.002
CVE-2026-10648
NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion
Published 2026-06-29 · Modified
6.2EPSS 0.002
CVE-2026-10663
Use-after-free / double-free of the root USB device in the experimental USB host stack
Published 2026-07-12 · Analyzed
6.1EPSS 0.002
CVE-2026-4179
stm32: usb: Infinite while loop in Interrupt Handler
Published 2026-03-14 · Analyzed
6.1EPSS 0.001
CVE-2026-1681
net: Stack Overflow with Ping (to own IP Address) via Shell
Published 2026-05-12 · Analyzed
6.1EPSS 0.001
CVE-2020-10072
Improper Handling of Insufficient Permissions or Privileges in zephyr
Published 2021-05-24 · Modified
5.9EPSS 0.002
CVE-2020-10059
UpdateHub Module Explicitly Disables TLS Verification
Published 2020-05-11 · Modified
5.8EPSS 0.012
← Prev4 / 5Next →