VendorsZephyrprojectzephyrall versions
Vulnerabilities

Zephyrproject Zephyr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2020-10066
Incorrect Error Handling in Bluetooth HCI core
Published 2021-05-24 · Modified
5.7EPSS 0.002
CVE-2020-13602
Remote Denial of Service in LwM2M do_write_op_tlv
Published 2021-05-24 · Modified
5.5EPSS 0.003
CVE-2026-10645
Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image
Published 2026-06-22 · Modified
5.5EPSS 0.002
CVE-2026-10670
User-triggerable kernel NULL-pointer dereference (DoS) in `k_thread_name_copy()` syscall verifier
Published 2026-07-14 · Analyzed
5.5EPSS 0.002
CVE-2026-10674
DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled
Published 2026-07-21 · Analyzed
5.5EPSS 0.001
CVE-2026-10679
Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)
Published 2026-07-21 · Analyzed
5.5EPSS 0.001
CVE-2026-10773
Out-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)
Published 2026-08-01 · Analyzed
5.4EPSS 0.003
CVE-2026-13481
Out-of-bounds read in PTP management TLV TIME parsing in Zephyr net PTP
Published 2026-08-26 · Analyzed
5.4EPSS 0.003
CVE-2026-10657
Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
Published 2026-07-05 · Modified
5.3EPSS 0.004
CVE-2026-10634
Use-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callback
Published 2026-06-15 · Modified
5.3EPSS 0.003
CVE-2026-1677
net: TLS 1.2 connections allowed on TLS 1.3 sockets
Published 2026-05-11 · Analyzed
5.3EPSS 0.002
CVE-2026-10647
Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
Published 2026-06-29 · Modified
5.3EPSS 0.002
CVE-2026-10664
Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)
Published 2026-07-12 · Analyzed
5.0EPSS 0.002
CVE-2026-10639
Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`
Published 2026-06-16 · Modified
4.8EPSS 0.002
CVE-2026-10659
NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume
Published 2026-07-07 · Modified
4.7EPSS 0.001
CVE-2026-10656
NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers
Published 2026-07-05 · Modified
4.6EPSS 0.003
CVE-2026-7007
Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image
Published 2026-07-24 · Analyzed
4.6EPSS 0.002
CVE-2026-10683
DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)
Published 2026-07-27 · Analyzed
4.6EPSS 0.002
CVE-2026-10642
Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control
Published 2026-06-24 · Modified
4.6EPSS 0.002
CVE-2026-10668
Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver
Published 2026-07-12 · Analyzed
4.6EPSS 0.002
CVE-2026-20435
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID: MSV-6118.
Published 2026-03-02 · Analyzed
4.6EPSS 0.001
CVE-2026-13479
Out-of-bounds read in LoRaWAN clock-sync AppTimeAns downlink handler
Published 2026-08-26 · Analyzed
4.3EPSS 0.002
CVE-2026-10644
Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer
Published 2026-06-28 · Modified
4.2EPSS 0.002
CVE-2021-3435
L2CAP: Information leakage in le_ecred_conn_req()
Published 2022-06-28 · Modified
4.0EPSS 0.002
CVE-2021-3433
BT: Invalid channel map in CONNECT_IND results to Deadlock
Published 2022-06-28 · Modified
4.0EPSS 0.002
CVE-2026-10636
Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`)
Published 2026-06-16 · Modified
3.7EPSS 0.003
CVE-2020-13599
Security problem with settings and littlefs
Published 2021-05-24 · Modified
3.3EPSS 0.002
CVE-2026-13480
Out-of-bounds read in LoRaWAN fragmented data block transport (FUOTA) downlink handler
Published 2026-08-26 · Analyzed
3.1EPSS 0.003
CVE-2026-10654
RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic
Published 2026-06-30 · Analyzed
3.1EPSS 0.002
← Prev5 / 5