Zephyr
Source repositories
CVEs (223)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-10658 | Hig | 0.46 | 7.1 | 0.00 | Jun 23, 2026 | bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the timestamped SDU header (8 bytes) from the inbound HCI ISO Data buffer via net_buf_pull_mem() without first checking buf->len. The upstream hci_iso() handler… | ||
| CVE-2026-10651 | Hig | 0.46 | 7.1 | 0.00 | Jun 23, 2026 | bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte attribute ID (a check of buf->len < 3) but then read a fourth byte, the data-element descriptor (type), via… | ||
| CVE-2025-10456 | Hig | 0.46 | 7.1 | 0.00 | Sep 19, 2025 | A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not… | ||
| CVE-2023-5563 | Hig | 0.46 | 7.1 | 0.00 | Oct 13, 2023 | The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception. | ||
| CVE-2023-5184 | Hig | 0.46 | 7.0 | 0.00 | Sep 27, 2023 | Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the Zephyr IPM drivers. | ||
| CVE-2023-4264 | Hig | 0.46 | 7.1 | 0.01 | Sep 27, 2023 | Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem. | ||
| CVE-2023-4259 | Hig | 0.46 | 7.1 | 0.01 | Sep 26, 2023 | Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code. | ||
| CVE-2021-3330 | Hig | 0.46 | 7.1 | 0.01 | Oct 12, 2021 | RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyr. Zephyr versions >= >=2.4.0 contain Out-of-bounds Write (CWE-787). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA… | ||
| CVE-2021-3581 | Hig | 0.46 | 7.0 | 0.00 | Oct 5, 2021 | Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Length Value (CWE-805). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8q65-5gqf-fmw5 | ||
| CVE-2020-13600 | Hig | 0.46 | 7.0 | 0.00 | May 25, 2021 | Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr | ||
| CVE-2020-10019 | Hig | 0.46 | 8.1 | 0.00 | May 11, 2020 | USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. This could be used by a malicious USB host to exploit the buffer overflow. See NCC-ZEP-002 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later… | ||
| CVE-2020-13603 | Med | 0.45 | 6.9 | 0.00 | May 25, 2021 | Integer Overflow in memory allocating functions. Zephyr versions >= 1.14.2, >= 2.4.0 contain Integer Overflow or Wraparound (CWE-190). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94vp-8gc2-rm45 | ||
| CVE-2026-10669 | Hig | 0.44 | 7.8 | 0.00 | Jul 14, 2026 | On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the architecture hook that verifies a user-mode-supplied buffer is accessible to the calling user thread with the requested permission — defaulted its return… | ||
| CVE-2026-10667 | Hig | 0.44 | 7.8 | 0.00 | Jul 12, 2026 | Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. Iteration over this list in k_object_wordlist_foreach() was performed under lists_lock using the… | ||
| CVE-2025-20747 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2025 | In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443;… | ||
| CVE-2025-20746 | Med | 0.44 | 6.7 | 0.00 | Nov 4, 2025 | In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441;… | ||
| CVE-2025-20696 | Med | 0.44 | 6.8 | 0.00 | Aug 4, 2025 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch… | ||
| CVE-2024-6258 | Med | 0.44 | 6.8 | 0.00 | Sep 13, 2024 | BT: Missing length checks of net_buf in rfcomm_handle_data | ||
| CVE-2024-3077 | Med | 0.44 | 6.8 | 0.00 | Mar 29, 2024 | An malicious BLE device can crash BLE victim device by sending malformed gatt packet | ||
| CVE-2023-2234 | Med | 0.44 | 6.8 | 0.01 | Jul 10, 2023 | Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host. |
- risk 0.46cvss 7.1epss 0.00
bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the timestamped SDU header (8 bytes) from the inbound HCI ISO Data buffer via net_buf_pull_mem() without first checking buf->len. The upstream hci_iso() handler…
- risk 0.46cvss 7.1epss 0.00
bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte attribute ID (a check of buf->len < 3) but then read a fourth byte, the data-element descriptor (type), via…
- risk 0.46cvss 7.1epss 0.00
A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exploit a flaw that causes the BLE target (i.e., the device under attack) to attempt to disconnect a fixed channel, which is not…
- risk 0.46cvss 7.1epss 0.00
The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception.
- risk 0.46cvss 7.0epss 0.00
Two potential signed to unsigned conversion errors and buffer overflow vulnerabilities at the following locations in the Zephyr IPM drivers.
- risk 0.46cvss 7.1epss 0.01
Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.
- risk 0.46cvss 7.1epss 0.01
Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.
- risk 0.46cvss 7.1epss 0.01
RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyr. Zephyr versions >= >=2.4.0 contain Out-of-bounds Write (CWE-787). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA…
- risk 0.46cvss 7.0epss 0.00
Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Length Value (CWE-805). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-8q65-5gqf-fmw5
- risk 0.46cvss 7.0epss 0.00
Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr
- risk 0.46cvss 8.1epss 0.00
USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. This could be used by a malicious USB host to exploit the buffer overflow. See NCC-ZEP-002 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later…
- risk 0.45cvss 6.9epss 0.00
Integer Overflow in memory allocating functions. Zephyr versions >= 1.14.2, >= 2.4.0 contain Integer Overflow or Wraparound (CWE-190). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94vp-8gc2-rm45
- risk 0.44cvss 7.8epss 0.00
On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the architecture hook that verifies a user-mode-supplied buffer is accessible to the calling user thread with the requested permission — defaulted its return…
- risk 0.44cvss 7.8epss 0.00
Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. Iteration over this list in k_object_wordlist_foreach() was performed under lists_lock using the…
- risk 0.44cvss 6.7epss 0.00
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443;…
- risk 0.44cvss 6.7epss 0.00
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441;…
- risk 0.44cvss 6.8epss 0.00
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch…
- risk 0.44cvss 6.8epss 0.00
BT: Missing length checks of net_buf in rfcomm_handle_data
- risk 0.44cvss 6.8epss 0.00
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
- risk 0.44cvss 6.8epss 0.01
Union variant confusion allows any malicious BT controller to execute arbitrary code on the Zephyr host.
Page 4 of 12