Vulnerabilities in zephyrproject

110 results
Vexday analysis

O Zephyr Project apresenta panorama atípico: 40 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente concentrada em um curto período. Nenhuma está sob exploração ativa (KEV) e não há críticas por CVSS, sugerindo severidade moderada; a fraqueza dominante (CWE-416 - use-after-free) aponta para falhas de gerenciamento de memória, típicas em projetos de firmware/RTOS. O risco imediato de exploração é baixo, mas o volume recente exige revisão arquitetural do código.

CVE-2026-10636LOWUse-after-free in Zephyr IPv4 IGMP send path (`igmp_send`)EPSS 0.3%CVE-2026-12233MEDIUMUninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contentionEPSS 0.3%CVE-2026-10593MEDIUMRemotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handlingEPSS 0.3%CVE-2026-10637MEDIUMUse-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD QueryEPSS 0.3%CVE-2026-10651HIGHOut-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)EPSS 0.3%CVE-2026-10685HIGHUse-after-free of GATT subscribe params in Bluetooth host CCC-write response handlerEPSS 0.3%CVE-2026-10773MEDIUMOut-of-bounds read in DHCPv4 client message-type name lookup (net_dhcpv4_msg_type_name)EPSS 0.3%CVE-2026-10658HIGHOut-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validationEPSS 0.3%CVE-2026-10641HIGHOut-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)EPSS 0.3%CVE-2026-11368HIGHUse-after-free in Bluetooth host ATT TX completion on disconnect mid-transferEPSS 0.3%CVE-2026-10656MEDIUMNULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlersEPSS 0.3%CVE-2026-10634MEDIUMUse-after-free in Zephyr native TCP `net_tcp_foreach()` due to dropping `tcp_lock` during the callbackEPSS 0.3%CVE-2026-11809LOWUpdateHub probe: uninitialized-heap out-of-bounds read of network-supplied metadataEPSS 0.3%CVE-2026-10774LOWPSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoSEPSS 0.3%CVE-2026-10848HIGHOut-of-bounds read in Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg)EPSS 0.3%CVE-2026-11811LOWSocket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoSEPSS 0.3%CVE-2026-10675MEDIUMBluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)EPSS 0.2%CVE-2026-12632MEDIUMOut-of-bounds read in Zephyr PTP message parsing from unvalidated message typeEPSS 0.2%CVE-2026-13734MEDIUMZephyr WireGuard mutates peer state before anti-replay check, enabling capture-replay endpoint hijackEPSS 0.2%CVE-2026-13735LOWWireGuard keepalive transport-data messages accepted without Poly1305 authenticationEPSS 0.2%