VendorsZephyrprojectzephyrany version
Vulnerabilities

Zephyrproject Zephyr any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

166CVEs
CVE-2024-5931
BT: Unchecked user input in bap_broadcast_assistant
Published 2024-09-13 · Modified
6.5EPSS 0.004
CVE-2024-3332
bt: host/smp: DoS caused by null pointer dereference
Published 2024-07-03 · Analyzed
6.5EPSS 0.004
CVE-2026-10675
Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)
Published 2026-07-21 · Analyzed
6.5EPSS 0.004
CVE-2020-10069
Zephyr Bluetooth unchecked packet data results in denial of service
Published 2021-05-24 · Modified
6.5EPSS 0.004
CVE-2026-10655
Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it
Published 2026-06-30 · Analyzed
6.5EPSS 0.004
CVE-2024-6444
Bluetooth: ots: missing buffer length check
Published 2024-10-04 · Analyzed
6.5EPSS 0.003
CVE-2024-6442
Bluetooth: ASCS Unchecked tailroom of the response buffer
Published 2024-10-04 · Analyzed
6.5EPSS 0.003
CVE-2026-5072
ptp: Potential Denial of Service via PTP Interval Shift
Published 2026-05-22 · Analyzed
6.5EPSS 0.003
CVE-2026-10593
Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling
Published 2026-06-28 · Modified
6.5EPSS 0.003
CVE-2026-10774
PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS
Published 2026-08-02 · Analyzed
6.5EPSS 0.003
CVE-2022-0553
Possible to retrieve uncrypted firmware image
Published 2023-01-11 · Modified
6.5EPSS 0.003
CVE-2026-2411
Bluetooth GATT notify/indicate enforces the wrong attribute's permissions, bypassing encryption/authentication requirements on characteristic values
Published 2026-08-01 · Analyzed
6.5EPSS 0.002
CVE-2026-10677
Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool
Published 2026-07-21 · Analyzed
6.5EPSS 0.001
CVE-2026-5590
net: ip/tcp: Null pointer dereference can be triggered by a race condition
Published 2026-04-05 · Analyzed
6.4EPSS 0.003
CVE-2026-5589
Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem.
Published 2026-06-04 · Analyzed
6.3EPSS 0.004
CVE-2026-10663
Use-after-free / double-free of the root USB device in the experimental USB host stack
Published 2026-07-12 · Analyzed
6.1EPSS 0.002
CVE-2026-4179
stm32: usb: Infinite while loop in Interrupt Handler
Published 2026-03-14 · Analyzed
6.1EPSS 0.001
CVE-2026-1681
net: Stack Overflow with Ping (to own IP Address) via Shell
Published 2026-05-12 · Analyzed
6.1EPSS 0.001
CVE-2020-10072
Improper Handling of Insufficient Permissions or Privileges in zephyr
Published 2021-05-24 · Modified
5.9EPSS 0.002
CVE-2020-10066
Incorrect Error Handling in Bluetooth HCI core
Published 2021-05-24 · Modified
5.7EPSS 0.002
CVE-2020-13602
Remote Denial of Service in LwM2M do_write_op_tlv
Published 2021-05-24 · Modified
5.5EPSS 0.003
CVE-2026-10645
Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image
Published 2026-06-22 · Modified
5.5EPSS 0.002
CVE-2026-10670
User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier
Published 2026-07-14 · Analyzed
5.5EPSS 0.002
CVE-2026-10674
DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled
Published 2026-07-21 · Analyzed
5.5EPSS 0.001
CVE-2026-10679
Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)
Published 2026-07-21 · Analyzed
5.5EPSS 0.001
CVE-2026-10773
Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)
Published 2026-08-01 · Analyzed
5.4EPSS 0.003
CVE-2026-13481
Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP
Published 2026-08-26 · Analyzed
5.4EPSS 0.003
CVE-2026-10657
Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
Published 2026-07-05 · Modified
5.3EPSS 0.004
CVE-2026-10634
Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callback
Published 2026-06-15 · Modified
5.3EPSS 0.003
CVE-2026-1677
net: TLS 1.2 connections allowed on TLS 1.3 sockets
Published 2026-05-11 · Analyzed
5.3EPSS 0.002
CVE-2026-10647
Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
Published 2026-06-29 · Modified
5.3EPSS 0.002
CVE-2026-10664
Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)
Published 2026-07-12 · Analyzed
5.0EPSS 0.002
CVE-2026-10639
Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`
Published 2026-06-16 · Modified
4.8EPSS 0.002
CVE-2026-10656
NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers
Published 2026-07-05 · Modified
4.6EPSS 0.003
CVE-2026-10683
DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)
Published 2026-07-27 · Analyzed
4.6EPSS 0.002
CVE-2026-7007
Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image
Published 2026-07-24 · Analyzed
4.6EPSS 0.002
CVE-2026-10642
Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control
Published 2026-06-24 · Modified
4.6EPSS 0.002
CVE-2026-10668
Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver
Published 2026-07-12 · Analyzed
4.6EPSS 0.002
CVE-2026-13479
Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler
Published 2026-08-26 · Analyzed
4.3EPSS 0.002
CVE-2026-10644
Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer
Published 2026-06-28 · Modified
4.2EPSS 0.002
← Prev4 / 5Next →