VYPR

Zephyr

by Zephyrproject Rtos

Source repositories

CVEs (223)

  • CVE-2023-4260MedSep 27, 2023
    risk 0.41cvss 6.3epss 0.01

    Potential off-by-one buffer overflow vulnerability in the Zephyr fuse file system.

  • CVE-2020-13598MedMay 25, 2021
    risk 0.41cvss 6.3epss 0.00

    FS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_stat. Zephyr versions >= v1.14.2, >= v2.3.0 contain Stack-based Buffer Overflow (CWE-121). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7fhv-rgxr-x56h

  • CVE-2026-1679HigMar 28, 2026
    risk 0.40cvss 7.3epss 0.00

    The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; oversized sends overflow `eswifi->buf`, corrupting kernel memory (CWE-120). Exploit requires local code that can call the socket send API; no remote attacker can…

  • CVE-2026-11368HigAug 4, 2026
    risk 0.39cvss 7.1epss 0.00

    The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When a buffer's last reference is dropped, its net-buf destroy callback defers the…

  • CVE-2026-10848HigAug 2, 2026
    risk 0.39cvss 7.0epss 0.00

    The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1, outlen - 1) and then…

  • CVE-2026-10641HigJun 17, 2026
    risk 0.39cvss 7.1epss 0.00

    Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) contains an out-of-bounds write. During Service Level Connection setup the HF sends AT+CIND=? and parses the AG's +CIND: response in cind_handle(), which assigns a…

  • CVE-2023-1902MedJul 10, 2023
    risk 0.38cvss 5.9epss 0.01

    The bluetooth HCI host layer logic not clearing a global reference to a state pointer after handling connection events may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, leading to a crash (DoS) or potential RCE on the Host layer.

  • CVE-2023-1901MedJul 10, 2023
    risk 0.38cvss 5.9epss 0.01

    The bluetooth HCI host layer logic not clearing a global reference to a semaphore after synchronously sending HCI commands may allow a malicious HCI Controller to cause the use of a dangling reference in the host layer, leading to a crash (DoS) or potential RCE on the Host…

  • CVE-2023-0359MedJul 10, 2023
    risk 0.38cvss 5.9epss 0.01

    A missing nullptr-check in handle_ra_input can cause a nullptr-deref.

  • CVE-2021-3320MedMay 25, 2021
    risk 0.38cvss 5.9epss 0.01

    Type Confusion in 802154 ACK Frames Handling. Zephyr versions >= v2.4.0 contain NULL Pointer Dereference (CWE-476). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-27r3-rxch-2hm7

  • CVE-2020-10072MedMay 25, 2021
    risk 0.38cvss 5.9epss 0.00

    Improper Handling of Insufficient Permissions or Privileges in zephyr. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Insufficient Permissions or Privileges (CWE-280). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/G…

  • CVE-2020-10023MedMay 11, 2020
    risk 0.38cvss 6.9epss 0.00

    The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause a memory corruption, resulting in denial of service or possibly code execution within the Zephyr kernel. See NCC-NCC-019 This issue affects:…

  • CVE-2026-16147MedSep 14, 2026
    risk 0.37cvss 6.8epss 0.00

    The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints. In work_handler_out() the active transfer buffer is obtained with udc_buf_peek() (which does not dequeue it); when a full max-packet-size…

  • CVE-2026-11743MedAug 7, 2026
    risk 0.36cvss 6.6epss 0.00

    The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its read and write paths with the test (offset + size) > data->size. Because offset is a signed off_t while size is unsigned, a negative offset is converted…

  • CVE-2026-10670MedJul 14, 2026
    risk 0.36cvss 5.5epss 0.00

    The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thread.c) calls k_object_find() on the caller-supplied thread pointer and then dereferences the returned struct k_object without checking it for NULL.…

  • CVE-2026-15893MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_reachable = 3*base/2 using integer…

  • CVE-2026-14696MedAug 31, 2026
    risk 0.35cvss 6.5epss 0.00

    When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame received on a bridge member interface is handled. For frames that must also be delivered to the local stack, the code…

  • CVE-2026-13734MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c validated the anti-replay counter too late. After AEAD decryption of a MESSAGE_TRANSPORT_DATA packet succeeded, the code committed several peer-state changes —…

  • CVE-2026-9728MedAug 24, 2026
    risk 0.35cvss 6.4epss 0.00

    The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct mbox_msg * pointer to…

  • CVE-2026-12631MedAug 18, 2026
    risk 0.35cvss 6.5epss 0.00

    The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_validate() in kernel/thread.c. Its default switch branch is the access-denied path, taken when k_object_validate() returns -EPERM…

Page 6 of 12